What Are Bank Credentials and What’s Your Liability?

Bank credentials are the pieces of information your bank uses to confirm you are who you say you are before letting you into an account: usernames and passwords, one-time codes, fingerprint or face scans, and security questions. Protecting them matters because federal law caps your losses at $50 if you report a stolen access device within two business days, raises that cap to $500 if you wait longer, and can leave you with the full loss after 60 days.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability

The Credentials You Actually Have

Most people think of credentials as a username and password, and that pair is still the base layer. The username is the public-facing identifier that links you to your account. Some banks let you pick one; others assign a number string. The password is the private half. When you log in, the bank’s server compares your entry against an encrypted version stored on its end. Your actual password is never sitting in a readable file somewhere at the bank.

The Electronic Fund Transfer Act treats a password as part of what it calls a “card, code, or other means of access” to your account. A bank can only hold you liable for unauthorized transfers if it first gave you a means to identify yourself as the authorized user, whether through a password, a fingerprint, or an electronic confirmation.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability

Multi-Factor Authentication

A password alone is no longer enough, and the FTC’s Safeguards Rule now requires financial institutions to use multi-factor authentication that combines at least two of three factor types: something you know, something you have, and something you are.2Federal Trade Commission. FTC Safeguards Rule – What Your Business Needs to Know

The most common second factor is a one-time code sent to your phone by text. These codes expire quickly, so intercepting one after the fact is worthless. Authenticator apps like Google Authenticator or Authy generate time-based codes on your phone without needing a cellular signal, which means they can’t be intercepted in transit.

Physical security keys are the strongest widely available second factor. These small USB or NFC devices use the FIDO2 standard to prove you have the key without transmitting any reusable secret. Unlike a text message code, a hardware key can’t be phished, because the key checks the website’s identity before responding. If a fraudster builds a convincing fake login page, the key won’t activate.

SMS codes are better than no second factor, but they have a known weakness. In a SIM swap, a criminal calls your carrier, impersonates you, and convinces the carrier to move your number to a new SIM. Every code your bank sends by text then goes to the attacker’s phone. If your bank offers authenticator apps or hardware keys, they are worth the minor inconvenience.

Biometric Identifiers

Biometric credentials use a physical trait — a fingerprint, facial structure, or voice pattern — as the check. Your phone’s secure hardware stores a mathematical representation of your biometric data and does the comparison locally. The bank never receives your raw fingerprint or face scan; it only gets a yes or no. A breach at the bank cannot expose your biometric data because the bank does not have it.

Security Questions

Knowledge-based questions ask for answers you provided when you opened your account: your first pet, your mother’s maiden name, the street you grew up on. Federal banking examiners have taken the position that reliable identity verification “generally does not depend solely on knowledge-based questions.”3Federal Financial Institutions Examination Council (FFIEC). Authentication and Access to Financial Institution Services and Systems The problem is that the real answers are often findable online. If your bank still uses security questions, treat them like passwords: give answers that are deliberately wrong but memorable to you, and store them in a password manager.

Credentials Are Not the Same as Account Numbers

People sometimes conflate credentials with account identifiers, and the difference changes what’s safe to share. Your account number and routing number are printed at the bottom of every check you write. They function like a mailing address: they tell the banking system where to send or pull money. Handing them over is routine for setting up direct deposit or receiving a wire.

Login credentials are different. Under the Gramm-Leach-Bliley Act, personally identifiable financial information you provide to a bank, or that results from your use of the bank’s services, qualifies as nonpublic personal information with specific privacy protections attached.4Cornell Law School. 15 USC 6809(4)(A) – Definition of Nonpublic Personal Information The practical rule: give out your account number when a transaction requires it, but never share a username, password, or one-time code with anyone for any reason, including someone claiming to be your bank.

How Credentials Get Stolen

Three attack methods account for most compromised bank credentials, and knowing them helps because your recovery options can depend on whether you took reasonable precautions.

Phishing is the simplest and most effective. You get an email, text, or call that looks like it came from your bank, warning about suspicious activity. The message points you to a fake login page. When you enter your credentials, the attacker captures them and uses them in real time on the real bank site. Some phishing operations even relay your one-time code in the same session, defeating basic multi-factor authentication. Hardware security keys are the one second factor that reliably stops this, because the key checks the site’s identity before it responds.

Credential stuffing exploits password reuse. When a breach at a retailer or social platform exposes millions of email-and-password pairs, attackers run automated tools that try each pair against banking login pages. If you used the same password for your bank as you did for a shopping site that was breached, your bank is now vulnerable even though the bank itself was never hacked. A unique password for every financial account removes the risk.

SIM swapping, as noted above, moves your phone number to a device the attacker controls, which lets them intercept text-message codes. Combined with a stolen password, it can walk them straight through multi-factor authentication built on SMS.

Your Liability for Unauthorized Transfers

The Electronic Fund Transfer Act sets a sliding scale of liability driven by how fast you report the problem:

  • Reported within 2 business days of learning about the loss or theft: your liability is capped at $50, or the amount of unauthorized transfers before you notified the bank, whichever is less.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
  • Reported after 2 business days but within 60 days of your statement: your liability can reach $500, covering transfers the bank can show it could have prevented if you had reported sooner.5eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E)
  • Reported more than 60 days after your statement date: you can lose everything transferred in that later window, provided the bank can prove those losses were preventable with timely notice.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability

The statute allows extensions for extenuating circumstances like hospitalization or extended travel, but don’t plan around that exception. The two-day clock starts when you learn of the loss, not when the unauthorized transfer happens. Checking statements regularly is the single most effective way to stay in the $50 tier.

What to Do If Your Credentials Are Compromised

Speed is the whole game, because every tier above is built on how fast you act. If you suspect someone has your credentials, whether from a phishing email you fell for, a breach notification, or transactions you don’t recognize, move through these steps in order:

  • Call your bank immediately using the fraud number on the back of your debit card or on the bank’s official website. Do not use a number from a suspicious email or text. Tell them you believe your credentials are compromised and ask them to freeze or restrict the account.
  • Change your password from a device you trust, not the one that may be compromised. If you used that password anywhere else, change it there too.
  • Review recent transactions and flag every transfer you did not authorize. Your bank will need this list to process a dispute under Regulation E.6eCFR. 12 CFR 205.6 – Liability of Consumer for Unauthorized Transfers
  • Switch to a stronger second factor. If you were relying on SMS codes, set up an authenticator app or hardware key. At minimum, put a PIN or passphrase on your account with your phone carrier so nobody can swap your number without it.
  • File a report with the FTC at IdentityTheft.gov, and a police report if the losses are significant. Those reports create a paper trail that strengthens your dispute with the bank.

When you’re recovering a locked account, banks typically verify your identity using the same information collected when you opened it: your name, date of birth, address, and a government-issued ID.7FFIEC BSA/AML Manual. Assessing Compliance with BSA Regulatory Requirements – Customer Identification Program Having those documents in hand speeds things up.

Business Accounts Do Not Get These Protections

The liability caps above apply to personal consumer accounts. Business accounts operate under a different legal framework. Article 4A of the Uniform Commercial Code governs commercial fund transfers, and it explicitly excludes consumer transactions covered by federal law.8Cornell Law School. UCC Article 4A – Funds Transfers Under Article 4A, a bank may not be required to reimburse an unauthorized business wire transfer if it followed commercially reasonable security procedures, even if the business reported the fraud the same day. A consumer who reports stolen credentials within two days loses at most $50; a business hit with the same attack on the same day could absorb the full loss. If you run a business account, the protections most people assume they have simply do not exist on your side of the line.