She’d recently opened a new checking and savings account with Citi, but the debit card the bank mailed to her never actually arrived. Today, she received three separate emails within about three minutes of each other, one confirming her debit card had been activated, another saying an online banking profile had been created, and a third stating the PIN had been changed. She didn’t actually see those emails until roughly 35 minutes after they were sent.
She already had an existing Citi online profile from before, so she tried logging in immediately once she saw the alerts. Her password no longer worked, forcing her to reset it before she could get back into her own account. Once inside, she found a $3,000 withdrawal already pulled from her savings account, along with a changed username on her profile and an unfamiliar phone number added to the account entirely.
💸 Take Back Control of Your Finances in 2025 💸
Get Instant Access to our free mini course
5 DAYS TO A BETTER BUDGET
A Card She Never Held, Used Within Minutes
The timeline here mattered enormously. The withdrawal itself had occurred about 25 minutes after the activation email went out, meaning someone had managed to activate a physical debit card she’d never received, change the PIN, set up a new online profile, and pull $3,000 out of her savings, all within a roughly half hour window before she’d even seen the alert emails notifying her anything was happening.
She immediately changed her username and password, turned on two factor authentication, and locked the compromised debit card once she discovered what had happened. That fast response limited further damage, but it didn’t undo what had already been taken in those first 25 minutes.
What Citi Told Her When She Called
She called Citi right away, eventually getting transferred to the fraud department after waiting to reach someone. They closed the compromised debit card along with her entire savings account, told her to visit a branch to open a replacement account, and said they’d investigate further and follow up with updates as they came in. They also told her that her online account, credit cards, and checking account remained secure, and that she could keep using her checking account for direct deposits in the meantime.
She wasn’t able to reach a branch before it closed that day, and since it was a Saturday, she was stuck waiting until Monday to actually open a new account in person. Five hours after that call with Citi, she could still see the supposedly closed savings account and the locked debit card sitting in her online banking exactly as before, with nothing indicating either had actually been deactivated on the back end despite what she’d been told over the phone.
Why the Speed and Access Point Don’t Add Up
She was genuinely confused about how someone managed to activate a debit card that had never reached her mailbox, create an entirely new online profile, change a PIN, and withdraw $3,000, all within such a tight window. It didn’t appear the withdrawal had happened through her existing online account either, since her original login credentials had still worked up until the point she’d reset them herself.
She’d also always understood debit cards to carry daily withdrawal limits, which made a $3,000 same day withdrawal stand out as unusually large for a single transaction on a newly activated card, particularly one tied to an account that hadn’t seen any prior legitimate activity establishing a spending pattern.
The Paperwork Chain She’s Stuck Navigating
She’d already filed an identity theft report with the FTC, but filing an actual police report was proving more complicated. Local police were requesting an affidavit from Citi showing her account balances before and after the theft, along with specific transaction details and location information tied to the fraudulent activity. USPS separately recommended including a police report when filing a mail theft claim, given that the card itself appeared to have been intercepted before ever reaching her.
That left her needing to visit the bank in person first, to obtain the documentation both the police and USPS were asking for, before either of those reports could actually move forward. Until Monday, she was effectively stuck holding screenshots of everything she’d found, worried the person responsible might still have some avenue to access more of her money given that nothing appeared to actually be locked down on Citi’s end despite what she’d been told over the phone.
What Reimbursement Typically Looks Like in Cases Like This
Bank reimbursement for unauthorized transactions generally depends on how quickly the fraud was reported and how clearly it can be shown the account holder didn’t authorize the activity. Given that she’d reported this the same day it happened, with a clear paper trail of emails, timestamps, and a card that had genuinely never reached her possession, her case had several strong factors working in her favor for eventual reimbursement.
That said, banks don’t always move quickly on these investigations, and having documentation showing the card was intercepted in the mail rather than lost or stolen after delivery could matter for how Citi ultimately classifies the fraud internally. The gap between what she’d been told over the phone, that the accounts were closed and secured, and what she could still see reflected in her own online banking hours later, was worth flagging directly with Citi again, since a genuinely closed account and card shouldn’t still be visible and apparently active from her end.
Featured on Cents + Purpose: