Every business has a category of risk it never writes down, because writing it down feels like inviting it. For a trading business that risk is not a bad month or a strategy that stops working. It is waking up and finding that someone else has the keys. So let me take the question seriously and answer it the way you would answer it about a warehouse or a bank account: what happens if my brokerage account is hacked, what does it actually cost, and what part of it can be decided in advance rather than in a panic?
This is an operations article, not a scare piece. I am going to use published figures from the FBI's Internet Crime Complaint Center and from the Securities Investor Protection Corporation, do my own arithmetic on them, and end with the part that belongs in your business plan. There is one finding in here that surprised me when I checked it, and it is the reason I wrote this rather than something more comfortable.
What Happens If My Brokerage Account Is Hacked, in Order
The sequence is duller and faster than most people imagine. There is rarely a dramatic moment. Access is obtained somewhere upstream of the broker, usually through your email, your phone number or a reused password, and then the account behaves normally except that the instructions are not coming from you.
What follows splits into two very different problems, and confusing them is what makes people handle this badly.
The first problem is theft. Funds move out, or positions are opened and closed in ways that transfer value elsewhere. This is the one everybody pictures, it is the one the numbers below measure, and it has a recovery process attached to it that is extremely time sensitive.
The second problem is loss of control, and it is the one traders underestimate. Even if not a cent leaves, you may be locked out while the broker investigates, resets credentials and verifies your identity. During that window your open positions are still open and you cannot touch them. For a business whose entire method is managing exposure, being unable to manage exposure is itself the loss, and it happens in every case, including the ones where the money comes back.
The Size of the Event, in Numbers Rather Than Fear
The FBI publishes an annual accounting of this, and it is the best public dataset a small operator has. In its 2025 Annual Report, the Internet Crime Complaint Center recorded 1,008,597 complaints and losses surpassing 20.877 billion dollars, a 26 percent increase in losses over 2024, with an average loss of 20,699 dollars across all crime types.
Buried in the trends section is the line that matters here. Account takeover accounted for approximately 4,700 complaints and 359.7 million dollars in losses in 2025.
Divide one by the other, which is my arithmetic and not the report's: the average account takeover complaint carries a loss of about 76,532 dollars. That is 3.7 times the average complaint of any type. Put differently, account takeover was 0.466 percent of all 2025 complaints but 1.72 percent of all 2025 losses, which makes it 3.7 times over-represented in money compared with its share of the count.
The comparison across routes is where the operational lesson sits. Running the same division on the report's other categories: personal data breach was 67,456 complaints and 1,314,923,988 dollars, an average of about 19,493. SIM swap was 971 complaints and 17,366,758 dollars, an average of about 17,885. Phishing and spoofing was by far the most common at 191,561 complaints, but only 215,843,126 dollars, an average of about 1,127.
So one account takeover costs roughly 68 times what the average phishing complaint costs. Phishing is the volume crime. Account takeover is the expensive one. If you are allocating a fixed amount of attention to security, that ratio tells you where to put it: not on the thousand small attempts, but on the one path that ends with somebody inside a funded account.
The Recovery Window Is Measured in Hours
Here is the part that changes behaviour, because it converts a vague sense of urgency into a number.
The FBI runs a Recovery Asset Team which operates something called the Financial Fraud Kill Chain, a process for freezing fraudulent transfers before they disperse. In 2025 the RAT initiated 3,900 incidents covering 1,163,919,846 dollars in attempted theft and froze 679,013,183 dollars, which the report states as a 58 percent success rate. Dividing the two figures myself gives 58.3 percent, which matches.
Now the other side of that number, which the report does not spell out and my arithmetic does. Forty-one point seven percent was not frozen. That is 484,906,663 dollars. Per incident, an average of 298,441 dollars was attempted, 174,106 was frozen, and 124,335 was simply gone.
The report is explicit about what determines which side of that split you land on, and it is not the size of the theft or the sophistication of the attacker. It is speed. In its own words, if you discover a fraudulent transfer, time is of the essence, and you should immediately contact your financial institution and request a recall of the funds along with any necessary indemnification documents. It also notes that different financial institutions have varying policies, so it is important to know what assistance yours will provide before you need it.
That last clause is an operations instruction disguised as a footnote. Knowing your institution's recall process is homework you do on a quiet Tuesday, not research you conduct at two in the morning while your hands are shaking.
One more detail worth having. Domestic kill chain actions numbered 3,574 incidents freezing 507,042,623 dollars, an average of 141,870 per incident. International actions numbered only 326 incidents but froze 171,970,560 dollars, an average of 527,517, which is 3.7 times the domestic average. International was 8.4 percent of incidents and 25.3 percent of the money frozen. Cross border cases are fewer and much larger, which is roughly what you would expect if the serious operations route funds offshore.
The Safety Net You Probably Do Not Have
This is the finding I did not expect, and it is the reason this article exists rather than a shorter one.
Most traders carry a background assumption that a brokerage account is insured in some way, in the loose manner that a bank deposit is. In the United States the relevant body is the Securities Investor Protection Corporation, and its protection is real: SIPC states a limit of 500,000 dollars, which includes a 250,000 dollar limit for cash.
Then read the exclusions, which are stated on the same page and are unambiguous. SIPC does not protect commodity futures contracts, unless held in a special portfolio margining account, or foreign exchange trades. Cash held in connection with a commodities trade is not protected by SIPC either.
Read that against what a gold trader actually holds. If your account is a spot gold or foreign exchange account, the SIPC figure covering it is not 500,000 dollars. It is zero. That is not a criticism of SIPC, which was built for securities custody and says so plainly, and it is not a claim about any particular broker. It is a statement about which of your assets fall inside the definition, and for this business most of them do not.
There is a second limit worth noting even for those holding securities. SIPC only protects the custody function of the broker dealer, meaning it works to restore securities and cash that were in your account when a member firm's liquidation begins. It is a remedy for a failed firm, not a theft insurance policy. It does not exist to reimburse you because a criminal used your credentials.
Outside the United States the architecture differs, and the honest position is that you have to check your own. What is generally true, and worth knowing, is that European retail protections address a different failure entirely: the ESMA measures introduced negative balance protection on a per account basis, a guaranteed limit on retail client losses, alongside leverage limits of 20:1 for gold and a margin close out rule at 50 percent of required margin. That protects you from owing more than the account holds. It does not put stolen money back.
The conclusion for your books is uncomfortable and clean. For a leveraged gold or foreign exchange account, assume the recovery of stolen funds depends on the speed of your reporting and the goodwill and policies of your broker, not on a statutory backstop. Plan as though there is no insurer, because for this instrument there very likely is not one.
The Second Loss Nobody Budgets For
Return to the loss of control problem, and price it the way you would price any other outage.
Take the standard unit of this business. If you risk one percent of equity per trade, one R equals one percent. Now suppose access is suspended for some number of days while identity is verified and credentials are reset.
At two trades a week, a three day lockout is about 0.9 trades not taken, a seven day lockout about 2.0 trades, a thirty day lockout about 8.6. That is the opportunity cost, and frankly it is the small half. The large half is that every open position runs unmanaged for the duration: 72 hours for a three day lockout, 168 hours for seven days, 720 hours for thirty.
Which produces the one genuinely useful operational conclusion in this whole subject. A position with a resting stop order continues to work while you are locked out, because the instruction is already sitting at the broker rather than in your head or your hands. A position without one is uncapped for the entire outage. The stop is not primarily a discipline tool here. It is the only part of your risk management that survives you losing access to the platform, and that is an argument for it that has nothing to do with psychology.
Note carefully what I am not saying. I am not telling you where to place anything, and no level, entry or target appears in this article. I am saying that an instruction already lodged with your broker behaves differently in an outage than an intention you are holding in your head.
The Continuity Plan, Written Before You Need It
Every item below is a decision you can make now, on a quiet day, and none of them requires knowing anything about the market.
Write down the recall procedure. Your broker's and your bank's. Phone number, the exact department, what documents they will ask for, what their stated timeline is. The IC3 guidance says to know this in advance, and the 58 percent figure is what it buys you.
Separate the email that owns the account. Almost every takeover route runs through an email address that also receives newsletters, shopping receipts and forum registrations. An address used for nothing else is not a clever trick, it is just a smaller attack surface.
Do not use SMS as your only second factor. SIM swap was only 971 complaints in 2025, which sounds negligible until you notice the average loss of 17,885 dollars and remember that a swapped number defeats every recovery flow that depends on it at once.
Keep withdrawal destinations locked and slow. Where a broker allows it, whitelisting withdrawal destinations with a cooling period turns instantaneous theft into an event with a delay in it, and delay is exactly what the kill chain needs.
Know which of your capital is where. Capital that is not in the trading account cannot be taken out of the trading account. I have written about building a cash reserve for your trading business as a drawdown measure, and it turns out to be a security measure too, which is the sort of thing you only notice when you look at two risks at the same time.
Verify the broker before any of this matters. The CFTC's registration check page makes the point that registration and a clean disciplinary record will not protect you from fraud, but that most scams involve unregistered entities. A regulated counterparty at least has a complaints process and a supervisor. An unregulated one has neither, and in a takeover you will be relying entirely on that process.
Decide today who you call first. Broker, then bank, then a report at ic3.gov or your national equivalent. Order matters because the freeze process starts at the receiving institution.
Get the free REX one page business plan, the sheet where the dull decisions like this one get written down while you are calm rather than invented while you are not. One email, no spam, unsubscribe anytime.
Get the free business plan →Frequently Asked Questions
What happens if my brokerage account is hacked, in one paragraph?
Two things happen at once. Money may be moved, which starts a recovery race where speed determines almost everything, and you lose control of the account while it is investigated and secured, which leaves open positions running unmanaged whether or not any money was taken. The first is the one people plan for. The second is the one that happens in every case.
Will I get my money back?
Nobody can promise that, and anyone who does is guessing. What the published figures show is the shape of it: across 3,900 Financial Fraud Kill Chain incidents in 2025 the FBI froze 58 percent of 1.16 billion dollars in attempted theft, leaving about 484.9 million unfrozen. Reporting immediately is the single lever the report identifies as decisive.
Is my forex or gold trading account insured?
In the United States, SIPC states that it does not protect foreign exchange trades or commodity futures contracts, other than futures held in a special portfolio margining account, and that cash held in connection with a commodities trade is not protected. So for a typical spot gold or FX account the covered amount is nothing. Outside the US, check your own regime rather than assuming an equivalent exists.
Does negative balance protection help if I am hacked?
No, and it is worth being clear about why. Negative balance protection under the ESMA measures caps how much you can lose below zero on a per account basis. It is a leverage safeguard. It has no bearing on funds removed by somebody who is not you.
What is the single highest value thing to change?
Dedicate one email address to the account and nothing else, and stop relying on SMS as the only second factor. Those two changes close the routes the IC3 categories describe most often, and neither costs anything.
Where did the figures in this article come from?
The complaint counts, loss totals, the account takeover figures, the Financial Fraud Kill Chain results and the reporting guidance are all quoted from the FBI IC3 2025 Annual Report at ic3.gov. The protection limit and the exclusions are quoted from SIPC's own page on what it protects. The leverage and negative balance measures are from ESMA's 2018 announcement. Every average, share, ratio and R figure is my own arithmetic on those published inputs, with the assumptions stated in the text.
Where REX Fits
REX Trading Signal is free to follow, with daily XAUUSD analysis and the reasoning stated before the trade, and an optional Kit for people who want the operating side written down properly. Nothing here is a promise of profit, and a channel that made one would be telling you something about itself rather than about the market.
The operating side is the whole point. The one page trading business plan template is the pillar this sits under, because a procedure you have not written down is a procedure you do not have. How to protect your account from hackers is the prevention half of this article, how your trading business survives a market shock is the same continuity thinking applied to the market instead of to your login, and how to manage multiple trading accounts matters here because the operational answer to concentration is rarely one account.
About the author. Rex writes REX Trading Signal. He is interested in the unglamorous half of this business, the costs, the controls and the review dates, on the view that the interesting half takes care of itself once the dull half is written down.
Disclaimer: This article is general educational content about operational and security risk in a trading business. It is not financial advice, not investment advice, not legal advice, and not a recommendation to use or avoid any broker, platform, product or security setting. It makes no accusation about, and no assessment of, any named or unnamed firm. The complaint counts, loss figures, account takeover figures, Financial Fraud Kill Chain results and reporting guidance are quoted from the FBI IC3 2025 Annual Report; the protection limit and the exclusions from SIPC; the registration guidance from the CFTC; and the leverage and negative balance measures from ESMA. Coverage, protections and reporting routes differ by country and by firm, and readers should verify their own. Every average, share, ratio and R figure is my own arithmetic on those published inputs on stated assumptions, and is not a measurement of anyone's account or results. No gold price level is quoted anywhere in this article. Trading leveraged products carries a high risk of losing money rapidly, and no entry, stop or target discussed should be treated as a signal. Consider your own circumstances and speak to a licensed professional in your jurisdiction before making decisions about your money.