A stolen credit card number can quickly turn into someone else’s shopping spree, but a federal consumer protection law puts a hard ceiling on what the actual cardholder owes. Under the Fair Credit Billing Act, a customer’s liability for charges neither made nor authorized tops out at $50, and in most real-world cases it lands at nothing. The protection applies whether a card was physically lost, the number was skimmed at a gas pump reader, or a fraud-monitoring system flagged an unfamiliar purchase halfway across the country. Older adults, who scammers frequently target by phone, mail, and online to harvest card numbers, are among the biggest beneficiaries of a rule that has been on the books for decades.
The Fair Credit Billing Act’s $50 Ceiling
The cap traces back to the Fair Credit Billing Act, the federal law that governs how credit card issuers must handle billing errors and fraud claims on open-end credit accounts. Once a cardholder formally reports a charge as unauthorized, the bank or credit union that issued the card cannot legally collect more than $50 toward that specific charge, no matter how much a thief actually spent. A criminal who runs up $4,000 in fraudulent purchases before the account is frozen leaves the cardholder responsible for, at most, a fraction of that total, and the issuer absorbs the rest as a cost of doing business.
The law draws a firm distinction between an unauthorized charge made by someone other than the cardholder and an ordinary billing dispute over something the cardholder actually purchased, such as a wrong dollar amount, a duplicate charge, or an item that never arrived. The Federal Trade Commission’s consumer guidance spells out both categories, along with the paperwork trail needed to invoke the $50 protection, including a written notice sent to the card issuer’s billing-inquiries address within 60 days of the first statement showing the disputed charge.
Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.
Zero-Liability Policies Layered On Top of the Federal Floor
Visa and Mastercard both publish zero-liability policies that go further than what the Fair Credit Billing Act requires, promising eligible cardholders $0 responsibility for unauthorized transactions on most consumer accounts. Those pledges are contractual commitments from the card networks themselves, not a rewrite of the underlying federal statute, which is why the $50 ceiling still matters as a legal backstop. If a specific card, account type, or circumstance falls outside a network’s zero-liability terms, or if an issuer’s own policy has an exception, the Fair Credit Billing Act’s $50 limit is what keeps the cardholder’s exposure from climbing any higher. In practice, the two layers work together: the private zero-liability pledge usually eliminates the cost entirely, and the federal law guarantees that even a gap in that private policy cannot cost more than $50.
Debit and ATM Cards Run on a Faster, Tighter Clock
Credit cards are not the only plastic in a retiree’s wallet, and the math changes considerably once a debit or ATM card is involved. The Electronic Fund Transfer Act, enforced in this area through the Consumer Financial Protection Bureau’s Regulation E, ties a cardholder’s liability directly to how fast the loss gets reported. A person who notifies the bank before a lost or stolen card is used for any unauthorized transaction owes nothing at all. Reporting within two business days after discovering the card missing caps the loss at $50, matching the credit card standard. Waiting longer, up to 60 days after an unauthorized transaction first appears on a statement, can push the cardholder’s exposure to $500, and liability becomes unlimited for a report made after that 60-day window closes, according to the FTC’s guidance on lost or stolen cards.
That sliding scale is the reason banking regulators and consumer advocates repeatedly urge account holders to check statements often rather than waiting for a paper bill to arrive by mail. A debit-card fraud alert missed for two months can turn what would have been a $50 problem into a total loss of whatever a thief managed to drain from checking, since a bank account does not carry the same borrowed-money cushion that a credit card provides while a dispute is pending.
The 60-Day Dispute Window and What Happens Next
Invoking the $50 credit card ceiling requires action, not just eligibility. A cardholder who spots an unfamiliar charge should notify the card issuer immediately, ideally in writing, describing the charge and stating plainly that it was not authorized. Federal rules give the issuer 30 days to acknowledge a dispute in writing and 90 days to resolve it, and during that window the disputed amount cannot be reported to a credit bureau as delinquent or used as grounds to raise the account’s interest rate. Many issuers also accept an initial phone call to freeze the disputed charge right away, though a written follow-up preserves the cardholder’s legal timeline under the Fair Credit Billing Act.
A fraudulent charge is sometimes the first visible sign of a broader identity-theft scheme rather than an isolated incident, particularly when a card number was harvested through a phone or online scam rather than a lost wallet. The Federal Trade Commission recommends filing a report at IdentityTheft.gov whenever a card is compromised, since the same stolen information that produced one fraudulent charge can resurface on other accounts weeks or months later. Reporting quickly, keeping copies of dispute correspondence, and confirming in writing that a card issuer removed the charge and any related fees closes the loop on a protection that federal law has guaranteed to cardholders for decades.
This article was produced with AI assistance and reviewed by The Financial Wire editorial team.
More Financial Reading
- What really happens to your joint savings account when you die?
- The ideal retirement withdrawal rate so your savings actually last



