How to Check If Your Credit Card Has Been Hacked

To check if your credit card has been hacked, log into your issuer’s app and read every transaction line by line (including charges under a dollar), verify that the email, phone, mailing address, and authorized users on your account haven’t been changed, and pull your free credit reports at AnnualCreditReport.com to see whether anyone has opened accounts in your name. Small unexplained charges, an unexpected decline, a fraud alert you didn’t trigger, or a replacement card you never asked for are the usual first signs. Federal law caps your liability for unauthorized credit card charges at $50, and the major card networks generally waive that, so the priority is catching the problem fast, not panicking about the bill.1Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card

Warning Signs Your Card May Be Compromised

The obvious sign is a large charge you don’t recognize. The subtler signs are the ones people miss.

Fraudsters commonly run a tiny test charge, anywhere from a penny to a few dollars, to confirm the card number works before attempting a real purchase. A small charge you don’t recognize is not a rounding error or a bank fee. Treat it as a red flag.

Other signals worth taking seriously:

  • Your card is declined even though you’re well under your limit. The issuer may have already flagged suspicious activity, or a thief may have burned through your available credit.
  • You get a text or push notification from your bank asking you to confirm a purchase you didn’t make.
  • Your issuer calls you about transactions you don’t recognize.
  • A replacement card arrives in the mail that you never requested, which can mean someone called the issuer pretending to be you.
  • Your paper or email statements stop arriving, which can mean a thief changed the contact information on your account to keep you in the dark.

Any one of these is enough reason to open the app and start looking.

Reviewing Your Transaction History

Your card issuer’s mobile app or online portal is the fastest way to spot unauthorized charges. Scroll through every transaction, not just the big ones. Those micro-charges are the test runs, and they often appear a day or two before a much larger fraudulent purchase.

Pay attention to the difference between pending and cleared transactions. A pending charge is a temporary hold, like a gas station authorization or hotel deposit, that hasn’t finalized. Cleared charges have posted for good. Thieves exploit the lag: several charges can pile up while earlier ones are still pending, draining your available credit before any single item looks alarming enough to trigger the issuer’s fraud system.

Unfamiliar merchant names trip people up. A charge from “SQ*MAIN STREET CAFE” is a Square payment processed for your local coffee shop, and “AMZN MKTP” is Amazon Marketplace. Plenty of legitimate businesses bill under a parent company, a payment processor, or an abbreviated descriptor that looks nothing like the storefront sign. Before assuming a charge is fraud, search the merchant string along with the amount. The real business usually surfaces quickly.

Telling Real Bank Alerts From Phishing

Your bank’s fraud detection watches your spending in real time and flags purchases that look out of character, like a transaction in a city you’ve never visited or a large purchase at a store category you don’t use. When it catches something, it sends a text or push notification asking you to confirm or deny a specific charge. Ignoring these alerts gives a thief more time.

Scammers send fake versions of the same alerts to steal your login. A real fraud alert references a specific transaction amount and merchant and asks for a simple yes or no. It will never ask you to provide your full card number, Social Security number, account password, or a one-time verification code inside the message. If a message asks for any of that, it’s a phishing attempt.

When you’re not sure, don’t tap the links. Open your bank’s app directly or type the URL into your browser yourself. If there’s a real alert on your account, you’ll see it there.

Checking Your Account Settings

This is the step most people skip, and it’s where you find evidence that someone is trying to take the account over rather than just skim a few charges.

Log in and check every piece of contact information on file: email address, phone number, and physical mailing address. If any of these have changed without your knowledge, a thief may have redirected your security alerts and replacement cards to themselves.

Then check your authorized users. Adding themselves as a secondary cardholder is one way a fraudster keeps access even after the primary card is canceled and replaced. Any name you don’t recognize should be removed.

While you’re there, confirm that any two-factor authentication you had turned on is still active. Disabling it is a common tactic attackers use after getting in, because it makes it easier to reset your password and lock you out later.

Checking Your Credit Reports for Wider Damage

A compromised card sometimes signals a larger problem. If a thief has enough of your personal information to use the card, they may have enough to open new accounts in your name.

You can pull your credit report from each of the three major bureaus, Equifax, Experian, and TransUnion, once a week for free at AnnualCreditReport.com. The free weekly access is now permanent.2Consumer Advice – FTC. Free Credit Reports

Look for accounts you didn’t open, addresses where you’ve never lived, and hard inquiries from lenders you never contacted. Hard inquiries from unknown lenders are particularly telling, because they mean someone applied for credit using your identity, and they stay on your report for up to two years. Under federal law, you have the right to dispute inaccurate information directly with the credit bureau, and the bureau must investigate and respond.3National Credit Union Administration. Fair Credit Reporting Act (Regulation V)

What You Owe If Charges Went Through

Federal law limits your personal liability for unauthorized credit card charges to $50, and that amount only covers charges made before you notify the issuer. Once you report the card compromised, you owe nothing for any further unauthorized use. Visa and Mastercard’s zero liability policies typically waive even the $50.1Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card4Visa. Visa Zero Liability Policy5Mastercard. Mastercard Zero Liability Protection Policy

For billing errors, including unauthorized charges, you have 60 days after your statement is sent to notify the creditor in writing. The creditor then has two billing cycles, and no more than 90 days, to investigate. During the investigation, the creditor cannot try to collect the disputed amount or report it as delinquent.6Office of the Law Revision Counsel. 15 US Code 1666 – Correction of Billing Errors

Debit Cards Work Differently

If the compromised card is a debit card rather than a credit card, the protections are weaker and speed matters more. Your liability depends entirely on how fast you report:

  • Within 2 business days, your maximum liability is $50.
  • After 2 business days but within 60 days of your statement, your liability can reach $500.
  • After 60 days, you can be liable for the full amount of unauthorized transfers that occur after that window closes.

The unlimited tier is what catches people. With a debit card, the money leaves your bank account directly, so waiting too long can mean permanent losses.7Consumer Financial Protection Bureau. Liability of Consumer for Unauthorized Transfers

What to Do the Moment You Find Fraud

Once you’ve confirmed an unauthorized charge or a clear sign of compromise, work through this order:

  • Lock the card in the issuer’s app. Most apps have an instant freeze toggle that disables the card in seconds without a phone call.
  • Call the issuer using the number on the back of the card or on the official website. Report the charges, cancel the card, and ask for a replacement with a new number. The issuer will open a fraud investigation and usually post provisional credits while it’s reviewed.8Office of the Comptroller of the Currency. Credit Card and Debit Card Fraud
  • Change your passwords. If the card was stored in any online account, update the login there. If you reused the password elsewhere, change it in those places too.
  • Send a written dispute to the address your issuer designates for billing inquiries, within 60 days of the statement date. This preserves your full protections under the billing error rules.6Office of the Law Revision Counsel. 15 US Code 1666 – Correction of Billing Errors
  • Update automatic payments. Every recurring subscription or bill tied to the old number will fail once the card is replaced, so list them and update each one.

Freezes, Fraud Alerts, and Identity Theft Reports

If the damage looks broader than one card, especially if unfamiliar accounts show up on your credit report, a credit freeze locks down your credit file so no one can open new accounts in your name. Freezes are free to place and free to lift at all three bureaus, and they stay in effect until you remove them. When you need to apply for credit yourself, you temporarily lift the freeze with a PIN or password and re-freeze afterward.9Consumer Advice – FTC. Credit Freezes and Fraud Alerts

A fraud alert is a lighter alternative. An initial fraud alert lasts one year and tells lenders to take extra steps to verify your identity before approving new credit. You only have to contact one of the three bureaus, and that bureau notifies the other two. A freeze is stronger; an alert is faster to set up and doesn’t require you to remember to lift it when you apply for a loan.9Consumer Advice – FTC. Credit Freezes and Fraud Alerts

When credit card fraud is part of a larger identity theft problem, such as accounts opened in your name or your information used elsewhere, file a report at IdentityTheft.gov. The site asks a series of questions and generates two things: an official Identity Theft Report and a personalized recovery plan with step-by-step instructions for your situation.10Federal Trade Commission. What To Do Right Away – IdentityTheft.gov

The Identity Theft Report is more than a formality. It serves as proof to businesses and credit bureaus that you’re a verified victim. With it, you can require credit bureaus to block fraudulent information from your report, and businesses must honor your requests to close accounts opened by a thief. Save or print both the report and the recovery plan right after completing the process.