Seeing a few cents hit your bank account can look harmless—or even like a small bonus. In reality, unexpected micro-deposits often mean someone is testing whether they can link your bank to an account they control. These “test” or “micro” deposits are a common step before account takeover and money theft. This guide explains how to recognize micro-deposit fraud, what it signals, and the exact steps to secure your accounts quickly.
What Are Micro‑Deposits?
Micro-deposits are small amounts—often between $0.01 and $0.99—sent to your bank account to confirm a link between that bank account and an app or service. Many legitimate services use them when you first connect your bank, but criminals use the same process to test stolen credentials or compromised information. After the deposits land, the sender typically asks the user to report back the exact amounts to verify account control.
Why Criminals Use Micro‑Deposits
Fraudsters deploy micro-deposits to silently check if they can:
- Link your bank to a fraudulent account at a payment app, crypto exchange, or marketplace.
- Validate stolen bank information from a breach, phishing kit, or dark-web dump.
- Confirm routing and account numbers before attempting larger ACH pulls or transfers.
- Avoid triggering alerts since tiny deposits rarely set off bank fraud systems compared with large withdrawals.
Legitimate vs. Suspicious Micro‑Deposits
Micro-deposits are not always fraud. The key is whether you recently connected your bank to a service or app. Use this quick comparison:
- Legitimate: You just signed up for or reconnected a known service (e.g., payroll, tax software, payment app) and expect verification deposits. The description matches the service you recognize.
- Suspicious: You weren’t linking anything. The description looks vague or unfamiliar, or the micro-deposits repeat across several days. You also receive emails or texts asking you to “verify amounts” for an account you didn’t create.
Common Clues in Your Bank Statement
Check the transaction details carefully. Potential red flags include:
- Unknown originators in the ACH description or company name you don’t recognize.
- Multiple tiny deposits in quick succession (e.g., $0.02 and $0.13) with no corresponding withdrawals you authorized.
- Repeating attempts across several days—attackers may try various services to find one that sticks.
- Generic descriptors like “ACCT VERIFY” or “TEST” with no brand you know.
Tip: If your bank supports alerts, enable notifications for any new ACH credit or debit, not just large transactions. Early alerts make a big difference.
How Micro‑Deposit Tests Lead to Account Takeover
Micro-deposits are rarely the end goal. Once verification works, criminals often move fast:
- Bank link confirmed: They prove they can receive and confirm the deposit amounts.
- Higher-risk actions: They initiate withdrawals, apply for financing, buy crypto, or move money between financial apps.
- Covering tracks: Funds hop across accounts, making recovery harder.
If they can’t verify through micro-deposits, they might pivot to social engineering—sending you phishing emails or texts to “confirm” the amounts and trick you into completing the verification step.
Immediate Steps If You See Suspicious Micro‑Deposits
Act quickly. Small transactions are your early-warning system.
- Do not confirm the amounts anywhere. Never enter the micro-deposit values in an app or reply to any message requesting them unless you initiated a legitimate connection.
- Lock down your bank login. Change your password, enable two-factor authentication (2FA), and review recent logins if your bank offers that feature.
- Contact your bank’s fraud department. Report the deposits, ask them to block unknown ACH originators, and request monitoring for new links or pulls.
- Search your email and texts. Look for “verify deposit,” “confirm your bank,” or “micro-deposit” to identify which service attempted the link. Do not click links—go directly to the service’s official site or app.
- Check financial apps you use (and don’t use). Review payment apps, brokerages, and wallets for new devices, linked accounts, or profile changes. Remove anything you don’t recognize.
- Rotate passwords and enable 2FA across key accounts. Prioritize email, bank, payment apps, tax software, investment accounts, and cloud storage. Use a unique, strong password for each.
- Review recent activity and statements. Look for small test pulls, card-not-present charges, password reset emails, and new-account notices.
- Consider placing a fraud alert or credit freeze. Especially if you see other signs of identity misuse (new accounts, change-of-address, hard inquiries).
Where Attackers Get the Data
Micro-deposit attempts usually follow an exposure of your information:
- Data breaches leaking emails, passwords, phone numbers, partial banking details, or identity data.
- Password reuse across sites—one leaked password can unlock multiple services through credential stuffing.
- Phishing and smishing that collect logins or trick you into enabling bank links.
- Public data and data broker profiles that supply contact info used to target you with convincing messages.
Preventive Controls That Actually Help
Focus on steps that reduce both the chance of compromise and the damage if one occurs:
- Use a password manager to create and store unique passwords for every account.
- Turn on strong 2FA (app or security key, not SMS when possible) for email, bank, payment apps, and any account that can move money.
- Set account alerts for new payees, external account links, ACH credits/debits, large transfers, and profile changes.
- Restrict ACH by asking your bank about ACH filters, blocks, and approved originator lists if your account type supports them.
- Harden email security—it’s the recovery hub. Add 2FA, remove old recovery methods you don’t use, and watch for forwarding rules you didn’t set.
- Reduce public exposure by opting out of data brokers and limiting contact information publicly posted online.
How to Read Micro‑Deposit Descriptions
Transaction memos often carry hints:
- Company or originator name: Search it with the words “ACH micro deposit” to see if it matches a known service.
- Trace/Company ID: Your bank can use this to identify the originator and block repeat attempts.
- Paired reversals: Some services send two small credits and one offsetting debit. If you didn’t initiate this, report it immediately.
When in doubt, contact your bank through the number on the back of your card or the official website—not through links in emails or texts.
Related Fraud Patterns to Watch
Micro-deposit testing often appears alongside other early-stage fraud signals:
- One-time password (OTP) spam where you receive numerous 2FA codes you didn’t request.
- Password reset emails from financial or payment services you use—or don’t use.
- Small unauthorized card charges (e.g., $1 authorizations) to test cards before larger purchases.
- New device sign-ins on accounts tied to your email.
What If The Micro‑Deposits Are Legitimate?
If you truly just linked a service:
- Confirm only within the official app or website—never by clicking emailed links.
- Verify the descriptor matches the service you expect.
- Delete the micro-deposits if the service instructs you and you’re confident the link is yours.
Still unsure? Wait. Contact the service’s official support and ask whether they initiated the deposits before providing the amounts.
Document Everything
Keep a short record if you suspect fraud:
- Dates and amounts of micro-deposits.
- Transaction descriptors and any originator IDs.
- Emails, texts, or in-app messages tied to verification.
- Bank case numbers and call logs.
This documentation helps your bank block specific originators, supports any dispute, and speeds police or FTC reports if needed.
Monitor for Identity and Credit Misuse
Account takeover attempts can expand beyond your bank into new credit lines or loans. Ongoing monitoring helps you spot trouble early, such as unexpected hard inquiries or new accounts you didn’t open. If you want a simple way to keep an eye on both credit changes and identity-related alerts, consider using a combined credit and identity monitoring tool. For more details on how this can fit into your protection plan, see SmartCredit for privacy, credit monitoring, and identity protection.
Step‑By‑Step Response Checklist
Use this quick checklist the moment you notice unexpected micro-deposits:
- Don’t verify or enter the deposit amounts anywhere.
- Secure your bank: change password, enable 2FA, contact fraud support, request blocks on unknown ACH originators.
- Secure your email: change password, enable 2FA, remove suspicious forwarding rules and recovery options.
- Search for verification messages to identify the attempting service; contact that service through official channels and revoke access.
- Audit payment apps and brokerages for unknown links or devices; sign out of all sessions.
- Turn on alerts for ACH activity, transfers, and profile changes.
- Rotate passwords on other high‑risk accounts; avoid reuse.
- Place a fraud alert or credit freeze if there are broader signs of misuse.
- Document everything and follow up with your bank for ongoing monitoring or ACH filters.
FAQs
Are micro‑deposits always a scam?
No. They are a standard verification method when you connect your bank to a legitimate service. They become risky when you didn’t initiate the connection or the descriptor is unfamiliar.
What amounts do fraudsters use?
Usually a few cents up to under a dollar, commonly two small credits. Patterns vary by platform and attacker.
Can I just ignore them?
Ignoring them can be risky. Unexpected micro-deposits suggest someone has enough of your information to attempt a link. Take the protective steps outlined above.
If there’s no money lost yet, should I still report it?
Yes. Reporting lets your bank block the originator and watch for follow-on attempts. Early reporting often prevents losses.
Conclusion
Unexpected micro-deposits are a quiet but critical signal that someone may be trying to attach your bank account to a service they control. Treat them as an urgent alert: don’t verify amounts, lock down your bank and email, notify your bank’s fraud team, and look for linked-account attempts across your financial apps. With strong passwords, 2FA, account alerts, and vigilant monitoring, you can turn these tiny transactions into a powerful early warning that helps you stop account takeover before it starts.
Good to Know
Micro-deposit tests often happen after a data leak or password reuse. If you see test deposits, also search your email for “verify your bank” or “confirm your account” messages—these clues can reveal which service the attacker tried to link.