Watch for ‘External Account Added’ Notices at Your Bank: What to Check Before Money Moves

Seeing a “New external account added” alert from your bank can be confusing—and dangerous. That one change can allow money to move out of your account to a destination you don’t control. This guide explains exactly what that alert means, how criminals exploit it, and the step-by-step checks to run before any money moves.

What “External Account Added” Usually Means

Banks let you link an outside account to transfer funds by ACH. When a new external account is added, your bank may:

  • Store the other bank’s routing and account number for ACH transfers.
  • Enable instant verification via a connection service (like an aggregator) so transfers can start quickly.
  • Send a confirmation email, SMS, or push notification to the primary account contact.

If you didn’t add that account, someone may have accessed your profile or convinced the bank you authorized the link. Treat the alert as a high-priority security event until you can confirm it’s legitimate.

Common Fraud Patterns to Recognize

  • Late-night linking, morning transfer: Fraudsters add an account off-hours, then push or pull money early the next day.
  • Instant verification via aggregator: Sign-in credentials are used to connect accounts quickly, skipping days-long micro-deposit waits.
  • Micro-deposit “verify and drain”: If instant verification isn’t available, they trigger tiny test deposits, confirm them, then attempt a larger transfer.
  • Small test transfer, then bigger move: A small outbound transfer may be used to test bank controls before a larger withdrawal.
  • Contact detail edits first: Attackers may update email or phone to intercept alerts before adding an external account.

Immediate Checks When You Get the Alert

  1. Do not click links in the alert. Open your bank’s app or type the site address manually to sign in.
  2. Check recent profile changes. Look for edits to email, phone, address, password, or recovery options. Note timestamps.
  3. Review “Linked accounts,” “Transfers,” and “Payees.” Capture the new external account’s last four digits, bank name (if shown), and when it was added.
  4. Scan pending and recent transfers. Look for test micro-deposits, small outbound transfers, or newly scheduled transfers.
  5. Check device and login history. Identify unfamiliar devices, IPs, or locations. Screenshot entries.
  6. Turn on all security alerts. Enable push, SMS, and email for transfers, payee changes, and login events.
  7. Change your password and rotate your 2FA method if available. Prefer an authenticator app over SMS.

How to Disable the New External Account

  • Remove or deactivate the link: In Transfers or External Accounts, delete the unrecognized account. If removal isn’t possible, set it to “inactive.”
  • Lock transfers temporarily: Some banks let you pause ACH or external transfers. Use this while you investigate.
  • Call your bank’s fraud line from the number on the back of your card. Ask them to block transfers to that account and note the incident.
  • Request a review of recent changes: Ask the bank to verify when and how the link was added (web, app, call center) and whether any aggregator authorization occurred.

Verify Whether a Legitimate Service Added the Link

Sometimes a budgeting app, brokerage, or payment service adds a connection you actually started but forgot about. To confirm:

  • Check aggregator connections: In your bank’s “Security” or “Connected apps” section, look for services that have account permissions. Remove any you do not use.
  • Review fintech apps you use: Open each app and check “Linked financial institutions” or “Bank connections.” Disconnect anything you don’t recognize.
  • Search your email for sign-ups, micro-deposit notifications, or “verify your bank” messages in the past two weeks.

What to Capture for Evidence

  • Screenshots of the alert and the external account details (last four digits, bank name, added date/time).
  • Login/device history pages and any contact-detail changes.
  • Pending/scheduled transfers and micro-deposit references.
  • Case numbers and names from any calls with your bank.

If Money Already Moved

  • Call the bank immediately: Ask about an ACH reversal or recall. These are time-sensitive and not guaranteed.
  • Report unauthorized transfers in the app or secure message center: Keep all case confirmations.
  • File with relevant authorities: Consider filing at IdentityTheft.gov if broader identity misuse is suspected, and keep a copy for your records.
  • Ask for account-level protections: Request transfer limits, out-of-band callbacks for new links, or a hard block on new external accounts.

Strengthen Your Bank Security Settings

  • Use a strong, unique password and update it if there’s any doubt it was exposed.
  • Enable 2FA with an authenticator app rather than SMS when possible.
  • Turn on high-sensitivity alerts: New payees, external accounts, contact changes, failed logins, and transfers above a threshold.
  • Set transfer limits: Lower daily and per-transaction caps to limit losses.
  • Audit connected services quarterly: Remove apps that no longer need access.

Check for Related Identity Risk

An external account link you didn’t add can be one sign of wider identity exposure. Attackers often try multiple angles at once.

  • Scan your email accounts for “new sign-in,” “password changed,” or “security alert” messages from other services.
  • Look for new credit inquiries or accounts you didn’t open, and monitor for address changes at financial institutions and the postal service.
  • Review your credit reports for unfamiliar activity and set fraud alerts if warranted.

Ongoing monitoring helps you catch follow-on fraud quickly. If you want combined privacy, credit, and identity alerts in one place, consider a dedicated monitoring tool that surfaces new credit pulls, account changes, and suspicious activity early. One option is described here: SmartCredit for privacy, credit monitoring, and identity protection.

How Attackers Add External Accounts

  • Credential stuffing: Reusing a password from a breached site allows attackers into your bank profile.
  • Phishing or smishing: Links to fake bank pages harvest credentials and OTPs.
  • Malware/keyloggers: Compromised devices leak passwords and session tokens.
  • Account recovery abuse: Attackers reset access using exposed personal data to pass knowledge-based questions.
  • Exploited aggregator authorizations: Granting a third-party app broad permissions can create unintended account links.

Preventive Steps Beyond the Bank

  • Unique passwords + password manager: Eliminate reuse so a single breach doesn’t open your finances.
  • Phishing hygiene: Type the bank URL directly, and never relay OTPs in calls or texts you didn’t start.
  • Device security: Keep OS and browser updated, enable disk encryption, and run reputable anti-malware.
  • Reduce personal data exposure: Remove your information from people-search sites that can fuel social engineering.
  • Email security: Use a masked email for banking and enable strong spam/phishing filters.

When to Replace Account Numbers

If unauthorized links or transfers keep appearing despite strong authentication, ask your bank about issuing a new account number and routing details. Pair this with updated passwords, fresh 2FA, and a review of all connected services to avoid re-linking by a compromised app.

A Quick Response Checklist

  1. Open your bank app directly; don’t use links in messages.
  2. Confirm whether you or a trusted service added the external account.
  3. Remove the link and pause external transfers if possible.
  4. Call the bank’s fraud number; request a block and internal review.
  5. Change your password and switch to an authenticator app for 2FA.
  6. Check for pending transfers and cancel them.
  7. Audit connected apps; revoke anything you don’t recognize.
  8. Turn on alerts for profile changes and transfers.
  9. Document everything with timestamps and screenshots.
  10. Monitor credit and identity signals for related abuse.

Conclusion

A single “External account added” alert is often the earliest sign of attempted theft. Act fast: confirm the change, remove the link, lock transfers, and get your bank’s fraud team involved. Then harden your account with stronger authentication, tighter alerts, and routine audits of connected apps. Keep an eye on broader identity signals so you can catch and stop related fraud early, before larger amounts move or new accounts get opened in your name.

Good to Know

A common fraud pattern is adding an external account late at night, verifying it with instant micro-deposits, and moving a small “test” transfer before a larger withdrawal the next day. Catching the first alert often prevents the second.