This article is provided for educational and informational purposes only. It does not constitute legal, financial, or tax advice, and no attorney-client relationship is formed by reading it. Laws, regulations, official guidance, and related information vary by jurisdiction, change frequently, and may have changed or become outdated since publication. Always verify current information with authoritative sources and consult a qualified professional about your specific circumstances. The author and publisher assume no liability for actions taken based on this information.
Key Facts
- Federal level: Federal law treats unauthorized credit-card use and unauthorized debit-card transfers under different liability and error-resolution rules.
- Federal level: A credit-card holder’s statutory liability for unauthorized use cannot exceed $50 when the conditions for liability are met, and an issuer may provide greater protection.
- Federal level: Debit-card liability can depend on when the financial institution receives notice, including a two-business-day rule for a lost or stolen access device and a 60-day statement rule for later transfers.
- Federal level: Regulation E generally requires a financial institution to investigate a qualifying debit-card error after receiving timely notice and to report the result to the consumer.
A fraudulent charge is a card transaction that the account holder did not authorize. The everyday phrase covers several situations, including a stolen physical card, copied card information, an account takeover, or a purchase made with card details online. It should not be confused with a billing disagreement about an authorized purchase.
The distinction between credit and debit matters because federal law uses two different frameworks. Unauthorized credit-card use is addressed principally by the Truth in Lending Act and Regulation Z. Unauthorized electronic transfers from a consumer asset account, including many debit-card transactions, are addressed by the Electronic Fund Transfer Act and Regulation E.
Credit-card fraud has a federal liability ceiling
For an unauthorized credit-card charge, federal law permits cardholder liability only when statutory conditions are satisfied. Those conditions include acceptance of the card, adequate notice of potential liability, a means to identify the authorized user, and unauthorized use before the issuer receives notice that misuse has occurred or may occur. Even then, the statutory ceiling is $50.
The issuer bears the burden of showing that use was authorized or that the legal conditions for unauthorized-use liability were met. Federal law does not prevent an issuer from offering a contract or policy that reduces the consumer’s liability below the statutory ceiling.
Regulation Z also separates unauthorized use from an ordinary billing error. That difference affects which dispute provisions apply, even though the same unfamiliar transaction may initially look like either problem on a statement.
Debit-card rules turn heavily on notice
Debit-card transactions draw money from a deposit or other consumer asset account, so the governing timing rules differ. Regulation E generally caps liability at the lesser of $50 or the amount of unauthorized transfers made before notice when the access device was accepted and the institution could identify the authorized user.
If a consumer does not report a lost or stolen access device within two business days after learning of the loss or theft, potential liability can rise to as much as $500 under the regulation’s conditions. Extenuating circumstances, such as extended travel or hospitalization, can extend the applicable period.
A separate 60-day rule applies after a periodic statement showing an unauthorized transfer is sent. The institution may avoid reimbursing losses that occur after that period if it proves those later losses would not have occurred but for the delay in reporting. The rule includes an extension when extenuating circumstances delayed notice.
These federal limits concern consumer liability; they are not a promise that every disputed transaction will be instantly classified as fraud. The financial institution may investigate whether the transfer was authorized and whether the notice and coverage requirements are met.
Regulation E provides an error-resolution process
Regulation E treats an unauthorized electronic fund transfer as an error that can trigger its investigation procedure. A notice generally must enable the institution to identify the consumer’s account and indicate why the consumer believes an error exists, including the type, date, and amount when possible.
For most covered errors, the institution must promptly investigate, determine whether an error occurred within 10 business days, and report the result within three business days after completing the investigation. When it cannot finish within 10 business days, Regulation E generally permits a longer investigation period if the institution provisionally credits the account within the prescribed time and gives the consumer use of those funds during the investigation, subject to specified exceptions and variations.
If the institution determines that an error occurred, it generally must correct the error within one business day after that determination. If it concludes there was no error or a different error, it must provide a written explanation and tell the consumer that supporting documents are available on request.
Fraudulent charges can point to a broader identity problem
Card fraud can result from physical theft, card skimming, stolen online credentials, or account takeover. An isolated merchant-name mismatch, however, does not by itself establish criminal fraud; payment descriptors and authorized recurring charges can also be unfamiliar.
When stolen identifying information is involved, the issue may overlap with federal identity-theft reporting. That is a related reader task, not a substitute for the card issuer’s dispute and investigation process.
“Fraudulent charge” is not one national criminal charge
The phrase describes an unauthorized transaction, not a single criminal offense with one nationwide set of elements. Conduct involving stolen card information may implicate federal or state criminal statutes, but the applicable charge depends on facts such as the method used, location, amount, and governing jurisdiction.
The consumer-protection rules discussed here answer a narrower question: how federal law allocates potential account-holder liability and structures certain dispute procedures. They do not determine whether a particular person committed a crime.
Sources
- 15 U.S.C. § 1693g: Consumer liability for unauthorized electronic fund transfers
- CFPB Regulation E § 1005.6: Liability of consumer for unauthorized transfers
- CFPB Regulation E § 1005.11: Error-resolution procedures
- 15 U.S.C. § 1643: Liability of holder of credit card
- CFPB Regulation Z § 1026.12: Special credit-card provisions
- Office of the Comptroller of the Currency: Credit-card and debit-card fraud