If a transaction isn't yours, act before it disappears. Use the institution's official app or the phone number on your card or statement, secure the account, save the transaction details, and report the problem to the institution that moved the money. If the payment is still pending, ask whether it can be stopped or recalled.
The recovery process depends on the payment rail. Credit-card billing errors generally fall under the Fair Credit Billing Act (FCBA). Many consumer debit-card and ACH transactions fall under Regulation E. PayPal, Venmo, and Zelle apply their own procedures, and a confirmed cryptocurrency transfer usually can't be reversed on the blockchain.
This guidance is for U.S. consumer accounts. Business accounts, wire transfers, and transactions outside the United States can follow different rules.
Start by identifying what happened
An unfamiliar transaction isn't automatically unauthorized. A merchant may use a different billing descriptor, a household member may have used a shared account, or a subscription may have renewed. Check the date, amount, receipts, and subscription history, but don't let that check delay a fraud report if the transaction remains unexplained.
| Payment or situation | Contact first | What determines the outcome |
|---|---|---|
| Credit-card charge you didn't make | Card issuer | The FCBA written billing-error process and the issuer's terms |
| Debit-card or ACH transaction you didn't authorize | Bank or credit union | Whether Regulation E applies, how the account was accessed, and when you reported it |
| PayPal, Venmo, or Zelle payment | App and linked bank or card issuer | The facts, funding source, and platform policy |
| Payment you sent after a scammer persuaded you | Payment provider and funding institution | Whether recovery is available and how the provider classifies the payment |
| Cryptocurrency transfer | Exchange or wallet provider, then IC3 | Whether the account or withdrawal can be secured before a blockchain transfer is confirmed |
Use precise language when you report the problem:
- "I did not initiate this transaction." This describes a likely account takeover, stolen card, or unauthorized debit.
- "I approved the payment after someone deceived me." This describes a scam payment that you authorized yourself. It may still be recoverable, but it will be investigated differently.
- "I don't recognize this merchant." This asks the provider to identify the charge before classifying it as fraud.
Mistakes that make unauthorized transactions harder to contain
1. Treating every unfamiliar merchant name as fraud - or ignoring it
Statement descriptors don't always match a store's public name. Check the transaction date, amount, receipt emails, subscription history, and purchases by authorized users.
Don't dismiss a small charge. Fraudsters sometimes test a card or account with a small transaction before attempting a larger one. Report anything you still can't explain.
2. Trusting an urgent message, caller ID, or verification code
Fake texts and emails may claim that an account is suspended, a payment is pending, or a refund is waiting. Their links can lead to convincing copies of bank or payment-app login pages. Caller ID can be spoofed, and voice cloning can make an impersonator sound familiar.
Don't use a link or phone number in an unsolicited message. Open the official app, type the institution's web address yourself, or use the number printed on your card or statement. Never share a one-time passcode with a caller. Verify an unexpected request through a separate, trusted channel.
3. Reusing passwords or relying only on SMS authentication
A password exposed in a retail, email, or social-media breach can help someone enter a financial account. Reusing it can also expose the email account used for password resets.
Use a different, long password for every financial and email account. A password manager can create and store unique passwords. When available, use an authenticator app or hardware security key instead of SMS alone. Ask your mobile carrier about an account PIN and number-transfer or port-out protections.
Protect the email account connected to your bank and payment apps as carefully as the financial accounts. Someone who controls your email may be able to intercept alerts and reset links.
4. Assuming a familiar device or network is safe
A professional-looking website doesn't prove that it's genuine. Avoid entering financial credentials on shared or unknown devices. Public Wi-Fi isn't automatically a fraud event, but a VPN won't protect you from a fake website, stolen password, or compromised device.
Keep your phone, computer, browser, and financial apps updated. Sign in through the official app instead of an unsolicited link.
5. Returning an unsolicited payment yourself
An unexpected payment can be part of a fake refund or overpayment scheme. If you send money back separately, the original payment may later be reversed, leaving you with a double loss.
Don't spend or independently return an unexpected payment. Contact the bank or app and ask how it wants the transaction handled. Never send a "verification" payment to receive a refund.
6. Treating person-to-person payments like credit-card purchases
P2P payments are intended for people who know and have verified each other. A mistyped recipient, fake seller, or payment made under pressure may not receive the same protections as an unauthorized credit-card charge.
Before sending money, verify the recipient's name, phone number, email address, and purpose through a separate channel. For a new recipient, pause rather than relying on an urgent message or a familiar profile photo.
7. Copying a crypto address without checking it
A blockchain transaction can be sent to the wrong wallet or network in seconds. Check the complete destination address and network on the device where you approve the transaction. Be wary of anyone who promises guaranteed returns, demands an upfront fee, or claims to be a celebrity or government official.
Never give a recovery phrase or private key to support staff, an exchange representative, or a supposed recovery specialist.
8. Reporting only to the merchant or waiting for proof
A merchant may be able to correct a duplicate charge or cancel a subscription, but contacting the merchant alone may not preserve your rights under a formal credit-card billing-error process.
Notify the card issuer or bank directly. Tell it whether the issue is fraud, a billing error, a canceled recurring debit, or a payment you were tricked into sending. Report it as soon as you notice it, even if you haven't collected every document.
Signs an account may be compromised
Look beyond the transaction itself. These signs often appear together:
- A new device, browser, or location in the account's security history
- Password-reset emails you didn't request
- A changed phone number, email address, mailing address, or security question
- An unfamiliar payee, external bank account, or transfer recipient
- A one-time passcode or login alert for an action you didn't start
- Several small charges followed by a larger payment
- ACH debits from a company you don't recognize
- A crypto withdrawal, wallet address, or network you never used
- A payment-app message asking you to move money to "protect" your account
Take screenshots of these alerts before deleting messages or resetting the account. Keep the original files, and don't forward suspicious links to other people.
What to do immediately
1. Record the facts
Save the statement or transaction screen, including:
- Amount, date, time, merchant, recipient, and transaction status
- Transaction or blockchain ID
- Screenshots of messages, emails, login alerts, and phone numbers
- Device or account changes you noticed
- Conversations with the suspected scammer
- The date and time you contacted the provider
- Case numbers, names, and instructions from support staff
Write a short timeline while the events are fresh. Keep a copy of every submission and avoid editing screenshots.
2. Contact the provider through an official channel
Call the number on the card, statement, or official website. If a payment is pending, ask whether it can be stopped or recalled. Ask the provider to:
- Lock or replace a card
- Block or investigate an ACH debit
- Remove an unknown device or payee
- Secure the payment-app account
- Freeze withdrawals where possible
- Open a formal fraud or billing-error claim
If the account is linked to more than one payment method, contact each affected institution. A dispute with a payment app doesn't necessarily replace a dispute with the bank or card issuer.
3. Secure connected accounts
Change passwords from a trusted device, starting with your email account if it may be compromised. Sign out of unknown sessions, remove unfamiliar recovery methods, and enable app-based multifactor authentication or a security key.
Contact your mobile carrier if your phone suddenly loses service or you receive a notice about a SIM or number change. Tell the bank if your phone number, email address, or device was taken over.
4. Use the process for the payment rail
Credit-card charges
For a formal FCBA billing-error dispute, send a written notice to the card issuer's billing inquiries address. Identify the account, disputed amount, transaction date, and reason you believe the charge is unauthorized. The notice must reach the issuer within 60 days after the first statement containing the error was sent.
A phone call can help stop further activity, but it may not replace the written notice required for the formal process. Keep a copy and proof of delivery. The issuer generally must acknowledge the dispute within 30 days unless it has already resolved it, and must resolve it within two billing cycles and no later than 90 days. The FTC's guidance on using credit cards and disputing charges explains the process.
If the statement went to an old address, the FCBA process also has a change-of-address condition: the creditor generally must have received written notice of the new address at least 20 days before the billing period ended.
Continue paying the part of the bill that isn't disputed. Don't simply stop paying the entire balance while the investigation is pending.
Federal law generally limits liability for unauthorized credit-card use to $50, although a card agreement may provide broader zero-liability protection. Meeting the 60-day deadline preserves the billing-error process; it isn't a promise that every transaction will be refunded.
Debit-card and ACH transactions
Report the transaction to your bank or credit union immediately and follow up in writing or through its secure message system. Ask about provisional credit, a stop or return request, replacement account details, and controls for future debits.
Regulation E applies to many consumer electronic fund transfers, including many debit-card and ACH transactions. If a lost or stolen debit card or other access device is involved, reporting the loss within two business days generally keeps the maximum statutory liability at $50. Reporting later can increase potential liability, and waiting more than 60 days after the statement showing the error was sent can leave you responsible for later transfers.
The two-business-day rule isn't a reason to wait when online credentials or an account number may have been compromised. Report the problem immediately and ask the bank which deadline applies to your facts. The Federal Reserve's official Regulation E commentary provides regulatory background.
If a recurring payment was previously authorized, explain when you canceled the service or revoked authorization. Revoke the authorization with the company and ask the bank about stopping future debits. Keep the cancellation confirmation. Stopping a future debit doesn't automatically resolve one that has already posted.
PayPal, Venmo, and Zelle
Report an account takeover or suspicious payment in the app and contact the bank or card issuer that supplied the funds. If an unauthorized PayPal transaction appears on a credit-card statement, tell the card issuer exactly what appears on the statement and follow its written billing-error process.
For Venmo or Zelle, the outcome depends on whether you didn't initiate the payment, approved it after being deceived, sent it to the wrong person, or bought from a seller. Platform protections, eligibility, and deadlines are policy-specific. Don't assume the FCBA's 60-day process applies just because the app was connected to a credit card or bank account.
Describe the event accurately. If you personally pressed "send," say that a scammer persuaded you to approve the payment and provide the complete timeline. If you didn't initiate it, say so plainly. In either case, ask whether the payment is pending and whether a recall or recovery request is available.
Cryptocurrency
Contact the exchange or wallet provider immediately if the account was hacked or a withdrawal is still pending. Request a withdrawal freeze, change your password, revoke unknown sessions, and preserve the wallet addresses, network, amount, and transaction hash.
A confirmed blockchain transfer usually can't be reversed by a bank or card issuer. An exchange may be able to secure a compromised account or cooperate with an investigation, but it can't promise to recover coins sent to an external wallet.
File a report through the Internet Crime Complaint Center's cryptocurrency information page and keep the report details. Be skeptical of anyone who contacts you afterward promising recovery for an upfront payment.
Deadlines people often confuse
These clocks are not interchangeable:
| Payment type | Key timing |
|---|---|
| Credit card | A written FCBA billing-error notice generally must reach the issuer within 60 days after the first statement containing the error was sent. The issuer generally has 30 days to acknowledge it and up to 90 days to resolve it. |
| Debit card or qualifying electronic funds transfer | Reporting a lost or stolen access device within two business days can preserve the lowest liability tier. The statement-based 60-day rule affects liability for later transfers. |
| Payment apps | There is no single federal 60-day chargeback rule that automatically applies to every PayPal, Venmo, or Zelle payment. The funding source, facts, and provider terms matter. |
| Cryptocurrency | A confirmed blockchain transfer has no ordinary card-style chargeback. Speed still matters because an exchange may be able to secure an account or pending withdrawal. |
If the provider denies the claim
Read the denial carefully. It may say the transaction was authenticated, that you authorized a transfer, that the notice was late, or that the claim falls outside the provider's policy.
Ask for the reason in writing and compare it with your timeline. Submit a concise response with the transaction record, account alerts, proof of cancellation, and a clear explanation of whether you initiated the payment. Use the provider's appeal or reconsideration process, and keep copies of every submission.
For cyber-enabled theft or cryptocurrency fraud, a report to IC3 creates a record for law-enforcement analysis, although it doesn't guarantee reimbursement. If an identity document, phone, or physical card was stolen, make a local police report when the bank, insurer, or other institution requests one.
Prevention checklist
- Turn on transaction, login, password-change, and new-recipient alerts.
- Review bank, card, and payment-app activity at least weekly.
- Use unique passwords stored in a password manager.
- Prefer an authenticator app or hardware security key over SMS when available.
- Set a carrier account PIN and ask about number-transfer protections.
- Reach financial institutions through their official apps, statements, or saved contact details.
- Verify new recipients by calling a known number, not by replying to the request.
- Review subscriptions and recurring ACH debits after every cancellation.
- Check the full crypto address and network before approving a transfer.
- Keep devices updated and don't enter credentials on shared devices.
- Choose a payment method with an appropriate dispute process when buying from an unfamiliar seller; P2P payments may offer less protection.
- Keep a secure record of account case numbers and important confirmations.
Frequently asked questions
Is a charge unauthorized if I don't recognize the merchant name?
Not necessarily. Check the descriptor, receipts, subscriptions, and authorized users first. If you still can't identify it, contact the card issuer or bank and let it investigate.
Does the 60-day rule apply to every unauthorized payment?
No. For credit cards, it generally refers to sending a written billing-error notice within 60 days of the first statement containing the error. Debit and ACH transactions have different Regulation E rules. Payment-app and crypto transactions don't automatically receive the same treatment.
What if I approved a payment because a scammer tricked me?
Report it immediately and describe exactly what happened. A payment you approved may be reviewed differently from one made by an intruder, but the provider still needs the full facts to determine whether recovery is possible.
Can a Zelle, Venmo, or PayPal payment be recovered?
Sometimes, but there is no single guarantee. Report the payment to the app and the linked bank or card issuer, ask whether it is pending, and follow the applicable dispute or recovery process. Eligibility can depend on how the payment was initiated and funded.
Can a cryptocurrency transaction be reversed?
Usually not after it is confirmed on the blockchain. Contact the exchange or wallet provider immediately, preserve the transaction hash, and report suspected fraud to IC3. Never pay an unsolicited recovery service upfront.
If you see a transaction you can't explain now, save the transaction screen, contact the institution that moved the money through an official channel, and ask for a case number.