Situation

Your statement shows an ACH debit to a company you do not recognize two weeks after a breach exposed bank account information.

Confirm the debit before assuming how it was authorized

Start by treating an unauthorized ACH or other electronic debit after a breach as a specific response problem rather than as proof that every part of your identity has been taken over. An unauthorized electronic debit can remove money from an existing account even when no new credit account is opened. Compare the descriptor, date, amount, and any recurring authorization against bills or services you actually use because merchant names can be unfamiliar.

Don't discard the notice. Note the arrival date and the exact data element or account it references, then move on to next steps. Once the bank confirms the debit is unauthorized, the important questions concern the transfer type, account access, and the institution’s error-resolution process.

Start with the bank or credit union where the debit posted. Identify the transaction date, amount, company name shown on the statement, and any trace or reference number the institution can provide. Report that you did not authorize the debit and ask which dispute process applies to that transfer rather than relying on the merchant name alone.

Notify the financial institution through its official fraud channel

The first move should reduce the most immediate pathway to misuse. Notify the bank or credit union promptly using the number on a known card, statement, or official app and ask how to dispute the specific transfer.

Resist the urge to tackle every downstream risk simultaneously. If login credentials were also exposed, secure online banking and recovery settings before focusing on unrelated breach benefits.

Timing matters with unauthorized electronic transfers. CFPB guidance tells consumers to notify the financial institution promptly when money is missing or an unauthorized transaction appears. Record the date of your first report, the channel used, and the case number; if the institution requests a written confirmation, send it through the verified process and keep a copy.

Ask whether credentials or only account details were exposed

The financial institution can investigate the electronic transfer, explain provisional-credit rules where applicable, block repeat debits, and decide whether an account-number change is appropriate.

Should an organization ask for ID documents, confirm it's a verified request before you send anything. Record the date of notice and follow written confirmation instructions the institution gives you so the dispute is not left as an undocumented phone call.

Ask whether the bank can block future debits from the same originator or whether a new account number is warranted. The right choice depends on how the debit was initiated and whether the underlying account information is believed compromised. Do not close an account impulsively if payroll, benefits, rent, or other legitimate payments still depend on it without first planning the transition.

Separate bank-account recovery from credit-file protection

Skip the freeze if this exposure has no realistic path to new credit; use it if it does. A credit freeze does not reverse an ACH debit because the misuse occurs inside an existing deposit account rather than through a new-credit application.

Get a dated baseline from annualcreditreport.com before starting credit monitoring, so future reports have context. Review linked external accounts, bill-pay settings, recurring debits, and later statements for additional transfers from the same originator.

Preserve the statement and every error-resolution message

Don't file this under 'later' — the records kept now are part of the actual resolution. Save the statement page, transaction identifier, institution case number, and any correspondence explaining the investigation or provisional credit.

Confirmed misuse means this is no longer a preparedness question — it's now recovery. CFPB guidance describes federal error-resolution rules for unauthorized electronic fund transfers, while the bank’s fraud department handles the specific account investigation.

Review surrounding transactions for smaller test debits, altered bill-pay recipients, or transfers to newly linked accounts. Also secure online banking and email if the breach involved credentials. Reversing one debit addresses the money movement; it does not automatically remove an attacker who still has account access or a valid authorization token.

Know why timing can matter for electronic transfers

One control rarely fixes every consequence here. Closing a debit card may not stop an ACH authorization tied directly to the account and routing numbers, so ask what control applies to the transfer you actually saw.

Also separate exposure from confirmed misuse. A forgotten annual subscription or legitimate processor can look suspicious, so verify the originator before filing an identity-theft narrative that does not fit the facts.

Ignore “refund” callers who ask you to move money

Expect follow-up scams that refer to the debit. After a breach, impostors may claim they can reverse the debit if you send money to a “safe” account or share a one-time banking code.

A legitimate recovery process should be verifiable through an established channel. A real investigation should remain visible after you independently call the institution; it should not depend on transferring money to the caller.

Check the next statements for repeat debits or account changes

Finish this stage by scheduling, not by planning to remember — calendar entries beat mental notes. Review the next statement and verify that any stop-payment, account change, provisional credit, or final correction promised by the bank actually occurred.

The incident is contained when the unauthorized debit has a documented resolution and the bank confirms the account controls needed to prevent a repeat.

Keep the breach notice separate from the transaction evidence but link them in your incident timeline. A breach explains how information might have escaped; the statement entry is the concrete event the bank investigates. That distinction makes your report clearer and prevents the disputed transfer from being treated as a vague concern about a security incident.

Primary sources used

Check the official source before you submit sensitive information.