Even after the bank fixes things, the attacker may still have your login or your data.
What to do
- Reset your online banking password from a known-clean device — make it unique to that bank
- Enable an authenticator-app or hardware-key 2FA (avoid SMS where possible)
- Set transaction alerts and lower daily transfer / international payment limits
- Turn on Confirmation of Payee / payee verification if your bank offers it
- Monitor statements and credit reports for at least 30 days and keep all evidence for any reimbursement claim
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers