Many older adults are nervous about online banking, and the nervousness is understandable. The combination of large sums of money, unfamiliar technology, and constant news about hacking and fraud creates a real and reasonable fear. Many people in their sixties and seventies have stayed away from online banking entirely, preferring paper statements and in-person visits to the branch, on the theory that the old-fashioned way is safer.
Here is the surprising truth: online banking is now actually safer than in-person banking for most fraud risks, as long as you follow basic security practices. The reason is that physical bank branches are vulnerable to robbery, mail interception, identity theft from stolen statements, dumpster diving, and a wide range of other physical attacks that online banking does not face. Online banking is vulnerable to its own set of attacks (phishing, password theft, malware), but those attacks are largely defeated by a small number of simple habits.
Federal regulations also strongly protect online banking customers. Under Regulation E, if you report fraudulent online banking transactions within 60 days of receiving the statement that shows them, your liability is generally zero — the bank has to refund the money. This is dramatically better protection than you have for in-person check fraud, mail fraud, or many other forms of financial loss. The legal regime is on your side, as long as you check your statements and report problems promptly.
The rest of this article is the six rules that, if you follow them, make online banking essentially safe — and the three myths about banking safety that do not actually help.
The single biggest risk to your online banking account is a stolen or guessed password. The fix is to use a strong unique password — meaning a password that is complex, hard to guess, and not used anywhere else. The best way to do this is with a password manager (see the password manager article in this series), which generates and stores complex passwords for you so you do not have to remember them.
If you are not ready to use a password manager, the minimum acceptable password for your bank account is at least 12 characters long, includes a mix of letters, numbers, and symbols, and is not based on any information someone could find about you (your name, birthday, address, family names). And it must not be used on any other website. The most common cause of online banking compromise is a password that was stolen from a different (less secure) website where the user had reused the same password they used at the bank.
Change your bank password if you have any reason to believe it might have been compromised — for example, if you receive a notification of suspicious activity, or if a website you use has been hacked, or if you have shared the password with anyone. Otherwise, you do not need to change your password regularly — that old advice has been revised, and changing strong passwords frequently does not improve security and may actually weaken it (because people often pick weaker variations of their old password).
Two-factor authentication (2FA) is the second most important security upgrade you can make to your online banking account. With 2FA enabled, even if a hacker steals your password, they cannot get into your account without also having your phone (which receives a verification code that the website asks for at login).
Almost every major bank now supports 2FA. To turn it on, log into your bank account, go to the Security or Account Settings section, find the option for Two-Factor Authentication or Two-Step Verification, and enable it. The bank will ask you to confirm your phone number, which they will use to send verification codes. After this is set up, you will need to enter a code every time you log in (or every time you log in from a new device, depending on the bank). The added time per login is about three seconds, and the added security is enormous.
If your bank gives you the option of an authenticator app instead of text message codes, use the authenticator app — it is more secure, especially against the SIM swapping attacks that can sometimes intercept text message codes. But text message codes are dramatically better than no 2FA at all, so if your bank only offers SMS, use SMS.
See the article on two-factor authentication elsewhere in this series for the full details on how to set this up. The 30 minutes you spend enabling 2FA on your bank account is one of the best uses of time available for protecting your money.
One of the most common ways online banking accounts get compromised is through phishing emails. The pattern: you receive an email that appears to be from your bank, warning you about suspicious activity, asking you to verify your account, or telling you that you need to update your information. The email looks official — the logo is right, the wording sounds bank-like, the formatting is professional. There is a link in the email that leads to a fake website that looks exactly like your bank's real website. You enter your username and password on the fake site, and the criminals now have your credentials.
The rule is simple: never click links in emails claiming to be from your bank. Ever. Even if the email looks completely legitimate. Even if it is urgent. Even if it threatens to close your account. The way to access your bank's website is to type the address yourself into your browser, or to use a bookmark you saved when you first set up online banking. Never use a link from an email.
If you receive an email that worries you and you want to verify whether there is a real problem with your account, do not click the link. Instead, open a fresh browser tab, type your bank's website address yourself (or use your bookmark), log in normally, and check for any messages or alerts inside your account. If there is a real problem, the bank will tell you when you log in directly. If there is no problem, the email was a scam. Either way, you have not given the criminals anything.
The same rule applies to text messages claiming to be from your bank. Banks do sometimes send legitimate text messages, but the safe practice is to verify any concerning message by calling the bank directly using the number on the back of your debit card — not a number from the message.
Real banks do not call you and ask for your password. Real banks do not call you and ask for the verification code that they just sent you. Real banks do not call you and ask for any of your security information that they should already have. If anyone calls you claiming to be from your bank and asks for any of these things, the caller is a criminal. Always.
The most common scam pattern: you get a call from someone claiming to be from your bank's fraud department, telling you that there has been suspicious activity on your account and they need to verify it is really you. They may already know some information about you (your name, last four of your account number, recent transactions) which makes them sound legitimate. They ask you to verify your password, or read them a code that just arrived on your phone, or transfer money to a 'safe account' to protect it. All of these requests are fraud. None of them are how a real bank operates.
If you receive a call that seems suspicious, hang up. Do not engage, do not verify anything, do not let yourself be talked into staying on the line. Then call your bank yourself, using the number on the back of your debit card or from your bank's official website. Tell them what just happened. They will confirm that the call was a scam and check your account for any unauthorized activity. The verification call you make from a known number is the only legitimate way to handle this kind of situation.
The single best thing you can do to protect yourself from financial fraud is to look at your bank account at least once a week. Most fraud is detected by the customer, not by the bank, and the sooner you spot a problem the easier it is to fix.
What to look for: any transaction you do not recognize, even small ones. Criminals often start with small test transactions to see if anyone notices, and if no one notices they escalate to larger ones. A $4 charge at a store you have never heard of is worth investigating, even though the dollar amount is trivial. A $400 charge a week later from the same source is much harder to fight than the $4 charge would have been.
Set up account alerts. Most banks let you set up automatic notifications by text or email for various account activities — large transactions, low balances, login from new devices, password changes, etc. Turning on these alerts gives you real-time visibility into what is happening with your account and lets you spot fraud within minutes instead of weeks.
If you find a transaction you do not recognize, contact the bank immediately. Federal law gives you strong protections, but those protections require you to report the problem within specific time limits (usually 60 days from the statement date for online banking, 30 days for credit cards). The sooner you report, the better your protection.
Use your own computer and your own phone for banking. Do not log into your bank account from a friend's computer, a hotel business center, a public library computer, or any device that belongs to someone else. Public computers can be infected with keyloggers or other malware that captures everything you type, including your bank password.
It is also a good practice to keep your own devices reasonably current with security updates. When your phone or computer prompts you to install a software update, install it within a few days. Most updates include security patches that fix vulnerabilities discovered since the last update, and unpatched devices are dramatically more vulnerable to attack.
The conventional wisdom about public WiFi (that it is dangerous to use for banking) has become less accurate as banking apps have improved their security. Modern banking apps use strong encryption that protects your traffic even on public WiFi. That said, it is still a good practice to use your own home WiFi or your phone's cellular connection for banking when possible, just to be safe.
Three commonly believed ideas about banking safety do not actually help much, and acting on them sometimes makes you less safe rather than more.
Myth one: avoiding online banking entirely is safer. As discussed at the start of this article, avoiding online banking does not eliminate fraud risk — it just shifts it to other forms (mail interception, in-person identity theft, paper statement theft, check fraud). It also makes it harder to monitor your account for unauthorized activity, because you can only check the account when you receive a paper statement once a month. The data shows that customers who use online banking and monitor their accounts weekly are dramatically less likely to suffer significant fraud losses than customers who rely only on paper statements.
Myth two: public WiFi is always dangerous for banking. This was true 10-15 years ago when banking websites used weaker encryption. Modern banking apps and websites use strong encryption (TLS 1.3 or similar) that protects your traffic from eavesdropping even on public WiFi. The bigger risk is the device itself — if you are on a malware-infected computer, public WiFi is the least of your problems. Use your own device, on any reasonably trustworthy network, and you are fine.
Myth three: big banks are safer than small banks. This is largely a myth. The security practices at major banks and well-run community banks and credit unions are roughly similar — both use the same kinds of encryption, fraud detection, and account protections. The differences between banks are mostly in customer service after a fraud incident: how quickly they resolve disputes, how easy they are to reach, how patient they are with customers who are not technically sophisticated. Some big banks are great at this and some are not; some small banks are great and some are not. Pick a bank based on the customer service experience rather than the assumption that bigger is safer.
Online banking is safer than most older adults think it is, and the steps to make it even safer are simple. Use a strong unique password (preferably from a password manager). Turn on two-factor authentication. Never click links in emails claiming to be from your bank. Never give your password or codes to anyone over the phone. Check your accounts weekly. Use your own devices.
If you do all six of these things, your risk of being defrauded through online banking drops to essentially zero. Federal regulations protect you against losses if fraud does happen and you report it promptly. The combination of personal security habits and legal protection is much stronger than what you have with paper-based banking, and the convenience is dramatically better.
If you have been avoiding online banking out of fear, this is the year to reconsider. Set aside a Saturday morning, follow the six rules above, and start using online banking with confidence. The peace of mind and the convenience are worth it, and the safety is real.