Yes, someone can steal your bank information from a wire transfer, and the risk usually has nothing to do with the wire network itself. When you send a wire, you hand over your full name, bank, routing number, and account number. Those are the same digits printed on the bottom of every check you write, and they’re all a thief needs to pull money out of your account through other payment systems that aren’t as tightly controlled as the wire network.
What You Actually Hand Over in a Wire
A domestic wire requires both parties’ full legal names, mailing addresses, bank names, ABA routing numbers, and account numbers. The information rides through systems like Fedwire or the Clearing House Interbank Payments System, and every intermediary bank that touches the transfer can see it. It also appears on the confirmation receipts both sides receive.
International wires ask for more: the recipient bank’s SWIFT/BIC code, and in many countries an IBAN that follows the ISO 13616 standard for cross-border account identification.1Swift. International Bank Account Number (IBAN) More data points in the transaction means more data points that can be compromised.
How Thieves Reuse Stolen Wire Details
A wire is a “push” transaction. You initiate it, and the money moves out. Other payment rails work the opposite way, on a “pull” basis, and that’s where your exposed numbers become dangerous.
The Automated Clearing House (ACH) network lets merchants and billers pull funds from your account using nothing more than your name, routing number, and account number. Someone who intercepts those details from a wire confirmation or email can set up unauthorized ACH debits and drain money over time. Under NACHA rules, consumers have 60 calendar days from the settlement date to return an unauthorized ACH debit, but you have to catch it first by watching your statements.
Fraudsters also generate electronic checks using stolen banking details. Unlike paper checks, which at least require the physical checkbook, an electronic check only needs the account holder’s name and bank numbers. Every physical security feature built into traditional check stock is bypassed.
Two Bank Services Worth Asking About
Positive Pay matches every check presented for payment against a list of checks you’ve actually authorized, comparing account number, check number, and dollar amount. Anything that doesn’t match gets flagged and won’t be paid without your approval. A counterfeit check written against your stolen numbers gets caught because that check number was never on the authorized list.
For ACH threats, many banks offer ACH debit blocks or filters on business accounts. Once enabled, the bank rejects all incoming ACH debits unless the originator is on your pre-approved list. Some versions let you set dollar limits per payee. If your account numbers are floating around from prior wires, an ACH block is one of the most effective ways to shut down unauthorized pulls before they happen.
Where the Information Actually Gets Intercepted
The banking network is heavily encrypted. Nearly every real-world interception happens in the channels people use to share wire instructions, which almost always means email.
Business Email Compromise is the most common method. An attacker gains access to a corporate or personal email account, often through a phishing link, and silently monitors conversations. When a wire is coming up (a real estate closing, a vendor payment, an investment deposit) the attacker sends a convincing email with substitute banking details. The sender believes they’re wiring money to the right place. They’re not. The funds land in an account the attacker controls, and by the time anyone realizes, the money has usually been moved again.
Man-in-the-middle attacks work similarly but target unencrypted data in transit, particularly over public Wi-Fi or compromised web portals. The attacker intercepts the banking coordinates and either harvests them for later use or alters the payment instructions in real time.
Red Flags Before You Send
The FTC warns consumers to be suspicious of anyone who pressures you into wiring money immediately or insists a wire is the only acceptable payment.2Consumer Advice – FTC. What To Know Before You Wire Money A few specific patterns matter:
- Last-minute changes to wire instructions. A legitimate title company or vendor almost never changes banking details at the eleventh hour. If updated instructions arrive close to a deadline, treat them as fraud until you verify independently.
- Slight email address changes. Attackers register domains that are one character off from the real one. An email from “closings@titlecompny.com” instead of “closings@titlecompany.com” is easy to miss under pressure.
- Urgency and secrecy. Utility impersonators, for example, threaten immediate shutoff to scare you into wiring money before you can confirm.2Consumer Advice – FTC. What To Know Before You Wire Money
The Regulation E Gap
This surprises most people: Regulation E, the federal rule protecting consumers from unauthorized electronic fund transfers, does not cover wire transfers. The regulation explicitly excludes wire and similar transfers from its definition of “electronic fund transfer.”3eCFR. 12 CFR 1005.3 – Coverage If you authorize a wire to a scammer who tricked you into sending it, Regulation E won’t help you get the money back.
Where Regulation E does help is with the secondary fraud that follows from stolen wire details. Unauthorized ACH debits and electronic check transactions initiated with your account numbers fall squarely under Regulation E’s consumer protections.4eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E) The liability framework is strictly time-based:
- Within 2 business days of learning your account information was stolen, your liability is capped at $50 or the amount of unauthorized transfers before you notified the bank, whichever is less.5eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E) – Section 1005.6
- Between 2 and 60 days, exposure can rise to $500 if the bank can show earlier notice would have prevented the loss.
- After 60 days from your statement date, you can lose everything the bank could have stopped had you reported sooner. No cap.5eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E) – Section 1005.6
The 60-day clock starts when the bank sends you the statement showing the unauthorized activity, not when you get around to reading it. Check statements regularly, especially after any transaction where you shared account details.
Why Wires Themselves Are So Hard to Reverse
Wires operate under Uniform Commercial Code Article 4A, which governs funds transfers between banks.6Legal Information Institute. U.C.C. – ARTICLE 4A – FUNDS TRANSFER (1989) The defining feature is finality. Once a wire is accepted and completed, it’s treated as a settled legal obligation. Unlike a credit card charge you can dispute months later, a completed wire creates no built-in right of reversal. A payment order can generally only be cancelled before the receiving bank accepts it, and once acceptance occurs, unwinding requires the cooperation of every bank in the chain.
A related trap: under UCC 4A-207, the receiving bank can generally rely on the account number alone to process a transfer, with no obligation to check whether the name and number refer to the same person, unless the bank has actual knowledge of the mismatch at the time of payment.6Legal Information Institute. U.C.C. – ARTICLE 4A – FUNDS TRANSFER (1989) Scammers sometimes provide an account number belonging to someone other than the name on the wire instructions, and the receiving bank may process it without catching the discrepancy.
For business accounts, Article 4A also puts weight on “commercially reasonable security procedures.” If a bank and its business customer agree on a verification protocol and the bank follows it in good faith, the payment order is treated as authorized even if a fraudster actually sent it.7Legal Information Institute. U.C.C. – ARTICLE 4A – FUNDS TRANSFER (1989) – Section 4A-202 In practice, businesses that skip email security training or multi-factor authentication tend to eat the loss.
Protecting Your Banking Information
Never send wire instructions by regular email. Standard email is unencrypted in transit, and a compromised email account gives an attacker everything they need. Use your bank’s secure messaging portal or an encrypted file-sharing service when transmitting account numbers and routing details.
The traditional advice is to verify wire instructions by calling the recipient at a known phone number, not the number listed in the email containing the instructions. Callback verification is better than nothing, but it has limits. If fraudsters have compromised someone’s communications deeply enough to alter wire instructions, they may also be spoofing caller ID. Some title companies and financial service providers now use identity verification platforms that send a security code to a verified phone number, confirming the person accessing the wire details actually controls that phone.
Layer your defenses beyond verification:
- Turn on multi-factor authentication for every email account and bank login connected to wire activity. BEC attacks start with email access, and MFA is the single most effective barrier.
- Set up transaction alerts so your bank texts or emails you whenever money moves. The faster you spot unauthorized activity, the less you lose under Regulation E’s time-based liability framework.
- Ask about Positive Pay and ACH blocks if your business account handles significant volume. These services cost little relative to the exposure they eliminate.
- Use a dedicated device for banking if you can. Keeping financial transactions off the same laptop where you open email attachments and browse the web reduces the attack surface.
If Your Information Has Already Been Compromised
Speed is everything. Recovery rates for wire fraud drop to single digits after 24 hours, so the first few hours are the only realistic window for getting money back.
Call your bank’s wire or fraud department first. If you catch the error within roughly 30 minutes of sending, the wire department may be able to cancel the transfer before it processes. After that, the bank can initiate a SWIFT recall requesting the receiving bank to freeze and return the funds. Recalls started within the first few hours have the highest success rate.
File a complaint with the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov. The IC3 operates a Recovery Asset Team established specifically to streamline communication with banks when victims wire money under fraudulent pretenses.8FBI. FBI Las Vegas Federal Fact Friday – Recovery Asset Team When IC3 receives a complaint involving a domestic wire to a fraudulent account, the Recovery Asset Team forwards the transaction details to the recipient bank and requests a freeze. You’ll need the transaction date, amount, account information, and details about who received the money.9Internet Crime Complaint Center (IC3). Frequently Asked Questions
Contact local law enforcement as well. IC3 reviews complaints and forwards them to appropriate agencies but does not conduct its own investigations, and local police can sometimes coordinate with banks faster than the federal process allows.9Internet Crime Complaint Center (IC3). Frequently Asked Questions
Once the immediate crisis is under control, place a fraud alert on your credit reports and monitor your bank accounts closely for the secondary fraud described earlier: unauthorized ACH debits and electronic checks drawn against your exposed account numbers. Ask your bank about closing the compromised account and opening a new one. Updating autopay is inconvenient. Leaving a compromised account number open is worse.