Protecting your money isn’t only about how you invest it or how much you save. It’s also about making sure you can reach it when you need it, safely, wherever you are. A traveler opens a banking app in a Barcelona hotel, switches on a VPN for safety, and gets locked out. Both sides were doing the right thing.
A Frozen Card in Barcelona
The scenario is common enough that bank support lines have a script for it. The customer connects through a VPN server in another country, signs in, perhaps tries a transfer, and the session ends with a forced password reset or a call to verify identity. Sometimes the card is frozen as well, which tends to happen at the worst possible moment: a hotel checkout, a rental car desk.
The usual conclusion is that VPNs and online banking don’t mix. That conclusion is wrong, but the reasoning behind it deserves a proper look, because the fix is simple once the mechanics are clear. The short version: a VPN protects the connection, but the server location it presents is something the bank reads very closely. Services also differ a lot in how predictable and clean their addresses are, which is why it pays to start from VPN services that have been through independent testing, such as the providers Gizmodo has assessed, rather than whichever free app shows up first in a store search.
What the Fraud Engine Sees
Banks don’t publish the exact rules their fraud systems apply, and they shouldn’t. What regulators do publish is the expectation behind those systems. In the United States, the FFIEC’s August 2021 guidance on authentication told financial institutions to assess risk continuously, using signals such as device, location and behavior, rather than trusting a password once at login. In the European Union, strong customer authentication under PSD2 has been mandatory for most online payments since the end of 2020, and banks layer their own risk scoring on top.
The IP address is one of the cheapest of those signals to read. It hints at a country, a network type (home broadband, mobile carrier, data center) and a history. A customer who logged in from Ohio this morning and appears to be in Singapore an hour later trips an “impossible travel” rule. An address belonging to a data center shared by thousands of anonymous users can trip another one, because criminals running account takeovers rely on exactly that kind of infrastructure.
And the stakes for banks are real. The FBI’s Internet Crime Complaint Center reported $16.6 billion in losses for 2024, the highest figure in the report’s history. Fraud teams are not paid to give the benefit of the doubt.
The Home-Server Rule
None of this means a VPN should stay off while banking. Public Wi-Fi in airports, cafés and hotels is still a poor place to send account credentials unprotected, and a VPN remains the simplest way to encrypt everything leaving the device on a network nobody controls.
The trick is to stop the VPN from making the customer look like someone else. In practice that comes down to one habit: connect to a server in the country where the bank account is held. A customer with a US bank, sitting in Barcelona, should pick a US server, ideally in or near their home region. To the bank, that looks a lot more like the customer than a Spanish hotel network would, and far more than a server in a country they have never visited.
A few further habits reduce friction. Pick one server location and keep using it, because consistency builds a profile the fraud engine recognizes. Avoid switching servers in the middle of a banking session, which can look like a hijacked connection. Check whether the provider offers a dedicated IP address: some banks treat shared data center addresses with suspicion, and an address used by one customer only sidesteps that problem. And when the app offers a travel notice, use it. It takes thirty seconds.
Free VPN apps are where the home-server rule breaks down most often. Many offer only a handful of locations, rotate addresses aggressively, or route traffic through networks with poor reputations, which is exactly the profile that gets flagged. Paid services aren’t automatically better, though, which is why independent testing matters more than price when choosing one. Testing by outlets such as Gizmodo tends to focus on leak protection, server reliability and audited no-logs claims, all of which matter for banking.
Two-Factor Is Still Doing Most of the Work
A VPN handles one part of the problem: an untrusted network between the phone and the bank. It does nothing against the most common way accounts actually get emptied, which is the customer being persuaded to hand over a code, approve a push notification or install a fake app.
That is why the authentication method matters more than any network setting. An authenticator app or a passkey is considerably harder to phish than a code sent by SMS, and SIM swap fraud has made SMS-based codes the weak link for many banks that still rely on them. Where a bank supports passkeys, switching is worth doing before the next trip, not during it.
The same logic applies to account alerts. Real-time notifications for logins, new payees and transfers above a small threshold turn the customer into a second fraud engine, and a faster one than the bank’s.
There is a broader shift underway too. Banks are gradually moving from “where is this login coming from?” toward “is this the same device and the same behavior as usual?” Device binding, behavioral biometrics and passkeys all point in that direction. As that change spreads, the IP address will matter less, and a well-configured VPN will cause fewer false alarms. Until then, the server location remains the setting that decides whether a traveler gets a smooth login or a phone call from the fraud department.
Your Investments Deserve the Same Protection
Most of the advice above is written with a checking account in mind, but the same rules apply to everywhere your money lives: brokerage apps, retirement accounts, savings platforms and crypto exchanges. These accounts often hold far more than your everyday card, and they are just as attractive to criminals. A hijacked investment account can be drained through a sale and a withdrawal, and recovering those funds is usually slower and harder than disputing a card charge.
Investment platforms also run their own fraud checks, so the home-server rule helps there too. A login from an unfamiliar country can delay a trade, block a withdrawal or trigger a manual review at exactly the moment you want to act. Long-term investors rarely need to trade from a hotel lobby, and that is a useful habit in itself: big financial decisions are better made at home, on a trusted network, with a clear head.
Before your next trip, a short money checklist covers both safety and peace of mind:
- Set a travel notice in your banking app and note your bank’s international support number.
- Switch to an authenticator app or passkey on your bank and investment accounts.
- Turn on real-time alerts for logins, new payees and withdrawals.
- Choose a reputable VPN and save a server in your home country as a favorite.
- Carry a backup card from a different bank, ideally one without foreign transaction fees.
- Keep a small emergency cash buffer so a frozen card never forces an expensive decision.
Financial wellness is built on habits like these. They cost almost nothing, they protect what you’ve saved and invested, and they let you enjoy the trip instead of spending it on hold with the fraud department.
