Overview
You land, connect to the airport Wi-Fi, open your banking app — and something is wrong. A verification screen you have never seen before. A code that never arrives. A card that works in one shop and not the next. It feels like the bank has spotted the foreign IP address and shut you out, and that is the story almost every article on this subject tells.
It is mostly not what happens. No major bank publishes a policy of blocking foreign logins, and a plain foreign residential IP is one of the weaker fraud signals you can generate. The things that genuinely lock travellers out are more mundane and more preventable: a one-time passcode sent to a phone number you can no longer receive on, an authentication rule written for people who never leave, and — on longer stays — a residency clause you agreed to without reading. This guide covers what actually triggers a lockout, how twenty-five banks and fintechs really behave abroad, and the honest answer to whether a VPN helps. For the wider picture of what else breaks when you travel, see our list of apps that stop working abroad — and if you are curious whether a changed location ever works in your favour, we tested VPNs against flight and hotel pricing separately.
What changed in this update
This page previously recommended buying a dedicated-IP VPN so your bank would believe you were still at home. Re-checking the evidence in August 2026, we could not support that advice, so we have removed it — along with an unverifiable claim about Wells Fargo's terms of service, a flatly incorrect statement about Chase travel notices, and a set of star ratings that had no methodology behind them.
What survives is the part that was right all along: why banks flag the traffic they flag. What is new is everything the original page missed — the SMS problem, the residency problem, and a per-bank table built from banks' own words rather than from forum lore.
Key Takeaways
- A foreign IP on its own rarely gets you blocked — no major bank publishes a policy of blocking foreign logins
- The most common avoidable lockout is a two-factor code sent to a phone number you can no longer receive on
- Travel notices are largely dead: Chase no longer accepts them at all, and most neobanks never wanted one
- A VPN generally makes bank access worse, not better. Its honest use abroad is encrypting public Wi-Fi
- Residency rules — not fraud detection — are what actually close nomads' accounts on a long stay
The story behind this rewrite — and it is user-reported
The most-repeated cautionary tale in nomad circles concerns a Charles Schwab customer whose account — roughly $47,000 — was frozen after logging in through a shared VPN server, reportedly taking more than two weeks and in-person identity verification to resolve.
We are keeping it here because it is a fair illustration of the risk, and flagging it clearly because honesty cuts both ways: this is user-reported. It circulates widely and consistently, Schwab has never confirmed it, and we could not verify it independently. What it is not is a reason to avoid Schwab — the account remains one of the best available to US travellers. It is a reason not to route your bank login through a shared VPN.
What actually triggers a block
Banks are not blocking travellers to be difficult — they are responding to fraud patterns that genuinely look like this. Understanding the signals matters, because two of the three below get worse when you route your connection through a VPN.
Shared IP addresses look like an attack
When dozens of people sign in from one VPN endpoint, a bank sees many unrelated accounts arriving from a single address in a short window — the exact signature of credential stuffing.
What it looks like in practice
You log in from a VPN server in New York. So do a few hundred other subscribers that hour. Your bank has no way to tell your session apart from theirs.
Impossible travel detection
Banks score the distance and time between consecutive logins. A jump no human could physically make reads as stolen credentials, regardless of whether a VPN is involved.
What it looks like in practice
You check your balance in Austin on Monday. On Tuesday you appear in Bangkok. A VPN makes this worse, not better — your phone sits in Bali while your exit node sits in New York, so you generate the impossible jump yourself.
Datacentre IP databases
Most commercial VPN servers run inside AWS, Google Cloud or DigitalOcean ranges. Banks buy and maintain lists of those ranges, and traffic from them is scored as higher risk than an ordinary home or mobile connection.
What it looks like in practice
This is the part people get backwards. A residential IP in Lisbon is a weaker fraud signal than a datacentre IP claiming to be in Ohio.
Why you keep getting challenged: Strong Customer Authentication
EU and UK rules — PSD2 Strong Customer Authentication — require two of three factors for remote electronic payments: something you know, something you have, something you are. The code must also be dynamically linked to that specific amount and payee, which is why the challenge appears per transaction rather than once per session.
Since Brexit the UK runs an equivalent regime under the FCA, so UK and EU issuers now sit in separate regulatory regimes for cross-border payments and can treat the same exemption differently. That is the honest explanation for most of what travellers experience as "my card randomly stopped working abroad" — and it is also why an unreachable one-time passcode channel is so damaging. The rules assume you can receive the second factor. Nothing about them assumes you are at home.
What we removed here, and why

Living the digital nomad dream until your bank decides otherwise... via GIPHY
The travel eSIM trap: when your bank texts a code you can't receive
This is the most common avoidable lockout, and it has nothing to do with IP addresses. Most travel eSIMs are data-only — no phone number, no SMS, no voice. Meanwhile a great many banks still send one-time passcodes to the mobile number on your file. Swap your SIM on landing, and you can be locked out of your own money in a country where you cannot phone support either.
How it happens

Waiting for a one-time passcode that is being delivered to a SIM card 6,000 miles away. via GIPHY
It is worth choosing your eSIM with this in mind rather than on price per gigabyte. Our travel eSIM comparison covers which providers sell a real phone number as an add-on, and the wider travel connectivity guide covers dual-SIM setup and keeping your home number alive while you travel.
Authentication that survives leaving the country
Interactive Brokers
IB Key push, a TOTP authenticator, a passkey or a physical security card — all independent of your carrier.
SEB and Swedbank (Nordic & Baltic)
Mobile BankID and Smart-ID are bound to the device, not the phone number. Smart-ID's own FAQ confirms it works anywhere in the world with an internet connection.
ING Germany
App push or photoTAN, with SMS being retired.
Deutsche Bank
photoTAN, migrating to the BestSign app.
Revolut, Monzo, Starling, Wise, N26, Bunq
Primarily app push and biometrics, with SMS only on the occasional flow.
Who still leans on SMS
Most large US banks — Chase, Bank of America, Wells Fargo, Citi, Capital One — and PayPal still default to an SMS passcode sent to your registered number. If you cannot receive it, the fallback is almost always a phone call to support, which is exactly what a data-only eSIM cannot do.
Do not try to fix this from abroad. Changing the registered phone number on an account is itself a high-risk security event — it looks identical to an account takeover — and it has been documented to trigger holds at PayPal. Change it before you leave, or not at all.
Four fixes, in order of how much they help
Move off SMS wherever it is offered
An authenticator app or in-app push approval is the single highest-value change you can make. TOTP codes are generated on the device and work with no signal at all.
Run dual-SIM: home SIM for SMS, travel eSIM for data
Keep the home line active so codes still land, set the eSIM as your data line, and switch data roaming OFF on the home SIM so it never quietly bills you.
Turn on Wi-Fi calling before you go
It lets your home number receive calls and, on most carriers, texts over any internet connection — a genuine fallback when there is no cellular coverage for that line.
Save offline backup and recovery codes
Every account that offers them. Print them or store them somewhere that does not itself need a second factor to open.
How 25 banks behave when you leave the country
Verified 14 August 2026 against banks' own help pages and terms. There are no scores here on purpose: a star rating implies a methodology we do not have. What follows is behaviour — what the bank does, what it says it does, and where we could only find travellers saying it. Anything marked unconfirmed means exactly that.
Showing 25 of 25 institutions.
| Bank | Foreign login behaviour | App works abroad? | 2FA method | Travel notice? | Residency risk | VPN |
|---|---|---|---|---|---|---|
| Neobanks & fintech | ||||||
Revolut Strictest residency rule of any account here — see the residency section | No documented IP block. Card use is confirmed by in-app push. | Yes — card works in 150+ countries | App push + PIN/biometric; SMS on some flows | Never required | High Must remain resident in the country the account was opened in | No benefit |
Wise | Blocked only from unsupported or sanctioned countries, not by IP reputation | Yes, except sanctioned countries | App-based 2-step + SMS | Not required | Medium Account is suspended while a country-of-residence change is reviewed | No benefit; unnecessary |
N26 | No documented IP block | Yes across the EU/EEA | App push + biometric | Not required | High Requires a residential address in a supported country | No benefit |
Monzo | No documented IP block; foreign card use works automatically | Yes; web app as a backup | App-based; SMS on some flows | Explicitly unnecessary | High UK-resident product — the current account must be closed on a permanent move abroad | No benefit |
Starling | No documented IP block | Yes | App-based | Not required | High UK-resident product | No benefit |
Bunq | No documented IP block | Yes across the EEA | App-based | Card region controls in the app | Medium EEA residency required | No benefit |
Chime | US-only product; the card works abroad once "International Transactions" is enabled | App works, but the account stays US-only | App / SMS | No — use the International toggle in the app | High US residents only | No benefit |
| US banks | ||||||
Chase | No IP block documented — behaviour is driven by the fraud model | Yes | App / SMS | No longer accepted (official) | Medium US address required | Liability |
Bank of America Liability — widely reported to block many VPN ranges (user-reported) | Fraud-model driven | Yes | App / SMS | Removed | Medium US address required | Liability |
Wells Fargo | Fraud-model driven | Yes | App / SMS | Removed | Medium US address required | Liability |
Citi | Fraud-model driven | Yes | App / SMS | Still offered (optional) | Medium US address required | Liability |
Capital One | Fraud-model driven; no notice needed | Yes | App / SMS | Removed | Medium US address required | Liability |
Charles Schwab Liability — a widely circulated report describes a ~$47,000 freeze attributed to VPN use (user-reported, not confirmed by Schwab) Still the strongest US account for travellers on fees — unlimited worldwide ATM fee rebates, no FX fees, 24/7 phone support | Fraud-model driven | Yes | App / SMS | Still offered | Medium US address required (a family or friend address is accepted) | Harmful |
| UK banks | ||||||
Barclays International support line: +44 1928 584421 | No notice needed; chip-and-PIN use confirms it is you | Yes | App / PINsentry | Not required (official) | High UK-resident product | Unconfirmed |
HSBC UK | No block documented; notifying makes handling smoother | Yes | App / SMS | Still offered | High UK-resident product | Unconfirmed |
Santander UK | No block documented; notify only for use outside the EU | Yes | OTP / SMS + app | Still offered — "Use card abroad" | High UK-resident product | Unconfirmed |
Lloyds / NatWest We could not verify either bank's current travel or foreign-login policy — check before you fly | Unconfirmed | Yes | App / SMS | Unconfirmed | High UK-resident products | Unconfirmed |
| EU & Nordic banks | ||||||
ING (DE / NL) Install the app before you leave — one traveller reported the Dutch app being unavailable from Estonia | No IP block documented | App runs abroad, but the app-store download can be geo-blocked (user-reported) | App push / photoTAN — SMS is being retired | Card region control in the app | Medium EU residency required | Unconfirmed |
Deutsche Bank The outside-Europe card block is sourced to Stiftung Warentest, not to Deutsche Bank — confirm with the bank | No IP block documented | Yes | photoTAN, migrating to the BestSign app | Cards reported blocked outside Europe until unblocked by phone | Medium EU residency required | Unconfirmed |
BNP Paribas | No IP block documented | Yes | App biometric login | None — "Option Travel" is a fee package, not a fraud notice | Medium EU residency required | Unconfirmed |
Swedbank | No block — BankID is bound to neither your IP nor your phone number | Yes | Mobile BankID — works over data, no SMS | Card controls in the app | Medium Nordic residency required | Unconfirmed |
SEB (SE / Baltics) SEB states its apps and Mobile BankID work abroad even with a foreign phone number, because they are not linked to the number. International line: +46 774 24 24 24 | Verified to work abroad | Yes | Mobile BankID / Smart-ID — works over data, no SMS | Card-abroad setting in the app | Medium Nordic or Baltic residency required | Unconfirmed |
| Payments & investment | ||||||
PayPal Changing your registered phone number while abroad has itself triggered security holds — do it before you go | Lockouts and step-up verification on foreign logins are consistently reported (user-reported; PayPal has published no clean fix) | Yes, but with friction | SMS / app; security key supported | Business accounts only (travel itinerary) | High Accounts are country-specific | Liability |
Interactive Brokers | No IP block — global by design | Yes | IB Key app, TOTP, passkey or security card. IBKR states its authenticator works independently of phone carriers and internet access | Not applicable | Low Built for cross-border clients | Neutral |
Coinbase Harmful — a VPN hides the block, not your residency, and Coinbase states it closes accounts it concludes are resident in a prohibited region (official) | Access is blocked from prohibited regions and restored when you leave | Yes in supported countries — not available in the UAE or Turkey | App / SMS / authenticator | Not applicable | High Prohibited-region rules apply to where you actually live | Harmful |
Reading the table
- An amber 2FA icon means the second factor can arrive by SMS to your registered number — the single biggest lockout risk if you swap to a data-only travel eSIM.
- High residency risk means the account is tied to living in a specific country, not merely to having opened it there. This is what ends most long-stay banking relationships.
- The VPN column is deliberately unglamorous. For almost every institution here, a VPN adds nothing to access and can subtract from it.
Charles Schwab: still recommended, but not for this
An earlier version of this page rated Schwab highly for VPN compatibility and listed it as confirmed to work with dedicated-IP VPNs. That was wrong, and we have removed it. Schwab is in fact the bank with the most widely circulated VPN-related freeze story — a roughly $47,000 hold attributed to a shared VPN login. That account is user-reported: it is consistently retold in nomad communities and Schwab has not confirmed it, so treat it as a caution rather than a documented policy.
Schwab still belongs on any US traveller's shortlist — unlimited worldwide ATM fee rebates, no foreign transaction fees, and 24/7 phone support are genuinely hard to beat. Recommend it on those grounds. Not on VPN compatibility.
Do you still need to tell your bank you're travelling?
Mostly, no — and this is where a lot of travel advice is years out of date. The travel notice is being retired across the industry, replaced by real-time fraud modelling and in-app card controls. Chase is unusually blunt about it:
Chase, in its own words
Dropped it entirely
- Chase — explicitly no longer accepted
- Bank of America
- Capital One
- Wells Fargo
Still offered
- Citi (optional)
- HSBC UK
- Santander UK (for use outside the EU)
- Charles Schwab
Never needed one
- Monzo — states so explicitly
- Revolut
- Starling
- Wise
- Barclays — states it is not required
- N26
What replaced the travel notice
The long-stay problem: residency rules that close accounts
Almost every article about banking abroad is written about a three-week holiday. The thing that actually ends nomads' banking relationships is not a fraud flag at all — it is residency. These are contractual conditions, published by the providers themselves, and no amount of careful login behaviour works around them.
Revolut
Residency in the country of opening is a condition of the account, and there is no transfer path between your own Revolut accounts.
If you're moving to a different country, you'll need to close your Revolut account to open one in another supported country… You cannot have multiple accounts, or keep your account if you're no longer a resident in the country it was opened in. If your relocation is temporary, your account will still be usable… You cannot transfer funds between your own Revolut accounts.
Official policy, quoted verbatim.
What it means for you: A permanent move means closing, emptying and reopening — and the balance has to leave via an external account on the way through.
Wise
Wise supports living in a different country than your ID, but the change itself puts the account on hold while it is reviewed.
Changing your country of residence triggers a compliance review. While the account is suspended you cannot add money, receive money, or pay bills by Direct Debit. Wise may ask for a government-issued right-to-reside document when the country on your ID differs from your address country.
Official policy, summarised from the provider's own help pages.
What it means for you: Survivable, but do not do it in the week your rent is due. Move money out first, then update the address.
N26
Requires a residential address in a supported EU or EEA country and does not onboard non-residents.
A residential address in a supported country is a condition of holding the account.
Official policy, summarised from the provider's own help pages.
What it means for you: Leaving the supported list ends the relationship. A widely repeated claim that N26 tolerates roughly 18 months abroad comes from third-party nomad guides, not from N26 — we could not verify it and would not plan around it.
Monzo & Starling
Both are UK-resident products, and both have tightened non-resident onboarding.
Monzo requires you to close your current account, and any ISA contributions to stop, once you are no longer a UK resident.
Official policy, summarised from the provider's own help pages.
What it means for you: Excellent travel accounts. Poor emigration accounts. Know which one you are doing.

Six months in, the fraud model has stopped caring. The residency clause has not. via GIPHY
What holds up over a long stay
On the evidence, three categories survive a genuinely mobile life. Wise, because it publishes a multi-jurisdiction residence list and a defined process for changing your address rather than treating it as an exception. Interactive Brokers, because it is built for cross-border clients and its authentication does not assume a phone carrier. And the Nordic and Baltic banks on BankID or Smart-ID, whose second factor is bound to your device rather than to a country or a phone number.
None of that is a VPN problem, and none of it has a VPN solution.
Should you use a VPN for banking abroad?
The short answer
This page used to recommend buying a dedicated IP so that your bank would think you were still at home. We no longer think that advice holds up, and we would rather say so than leave it standing. Here is the full ladder, worst to best.
A shared VPN IP
Hundreds of unrelated accounts signing in from one endpoint is the textbook signature of credential stuffing. This is the first mechanic described above, and it is correct — which is precisely why routing your bank login through a shared server is the worst of the options here.
A dedicated IP
Give the reasoning its due: a dedicated IP genuinely does solve the shared-IP problem, because nobody else is using it. But it is still typically a datacentre address, which banks score as higher risk than a home connection, and it does nothing whatsoever about impossible travel. No mainstream bank endorses one, and we could not find a single bank that requires one.
Your ordinary foreign connection
The hotel Wi-Fi or eSIM carrier IP you already have is a residential or mobile address, and it is a weaker fraud signal than any commercial VPN endpoint. For bank access specifically, doing nothing is usually the best available move. That is an unsatisfying answer, and it is the right one.
A VPN for public Wi-Fi encryption
Encrypting your traffic on an untrusted network is a real problem with a real solution, and it is completely separate from spoofing your location. This is where a VPN earns its place on this page — and the only place it does.
The distinction that matters
The one platform that spells out the consequence
Coinbase blocks access from sanctioned and prohibited regions outright, and its help centre is unusually direct about what happens next: "If, however, Coinbase concludes that you reside in a prohibited region or are violating applicable sanctions in any way, your account will be closed and Coinbase will take any other actions required by law." That is official.
Note what it turns on: where you reside, not which IP address you arrive from. A VPN can hide the block from you, but it does not change the fact the rule is written about. You would be tunnelling into an account that can then be closed. Worth knowing if you hold crypto and travel.
Note on sourcing: plenty of third-party articles state that Coinbase's terms of service explicitly forbid VPN use. We read the current US User Agreement and could not find any mention of VPNs, proxies or location masking in it, so we are citing only the prohibited-region policy above, which Coinbase does publish.
Where a VPN is genuinely worth paying for
Hotel, hostel, airport and café networks are shared, frequently misconfigured and occasionally hostile. Encrypting everything that leaves your laptop on those networks is worth doing whether or not you ever open a banking app. Our guide to public Wi-Fi security for remote workers sets out the same reasoning at length. Turn it on for the network, not for the bank.
NordVPN
Solid all-rounder for untrusted networks
- Strong track record on audited no-logs claims
- Reliable apps on every platform you travel with
- 30-day money-back guarantee
from $3/mo
Get NordVPNSurfshark
Cheapest way to cover every device you carry
- Unlimited simultaneous devices on one plan
- Useful if you travel with a laptop, phone and tablet
- Lowest entry price of the two
from $2/mo
Get SurfsharkPricing and disclosure
Before you fly: the seven-item lockout checklist
Nearly every banking problem travellers hit is cheaper to prevent than to solve. None of this involves buying anything, and all of it takes about an hour at your kitchen table with a working phone number and a working internet connection — the two things you are about to give up.
If it happens anyway: the lockout playbook
In order. The first two solve most cases, and both work from a data-only connection.
- 1
Open in-app chat before you try to phone anyone
Revolut, Monzo, Wise, Starling and N26 are chat-first and reachable over any data connection. This is faster than an international call and it works from a data-only eSIM.
- 2
If an SMS code will not arrive, change the channel, not the number
Try Wi-Fi calling to receive it on the home line, or switch that account to app-based 2FA from a device that is still signed in. Do not update the registered number from abroad — that is itself a security event.
- 3
If a card is declined, switch cards immediately, then investigate
Use the second card to complete whatever you were paying for. Sorting out the first one is a job for later that evening, not for the till.
- 4
Try the wallet token even when the card is frozen
Apple Pay and Google Pay tokens can keep working after a physical card is blocked — Monzo documents this explicitly. Provision both before you travel so the option exists.
The redundancy that actually works
Frequently Asked Questions
Will my bank block me for logging in from another country?
Should I use a VPN to access my bank abroad?
Can a bank close my account for using a VPN?
Do I still need to tell my bank I'm travelling?
What happens if my bank texts a code I can't receive abroad?
Which banks work best for digital nomads?
Can I keep my bank account if I move abroad?
Why does my card get declined for online purchases abroad?
What should I do if I'm locked out of my bank while travelling?
Is a dedicated IP better than a shared VPN IP for banking?
Does a VPN help at all when I'm travelling?
Can I just change my registered phone number to a local one?
Will my banking app even install abroad?
How many cards should I travel with?
Final thoughts
The uncomfortable conclusion of this rewrite is that the best thing most travellers can do about bank access is nothing at all. Use the connection you have, keep your second factor reachable, and let the fraud model see an ordinary person in an ordinary place. The elaborate setups — dedicated IPs, home-country tunnels, careful login choreography — solve a problem that is mostly imaginary while creating one that is not.
The problems that are real are boring: a text message you cannot receive, and a residency clause you did not read. Both are fixable in an afternoon before you leave, and neither is fixable from a hostel in another time zone.
References
- [1]Do I need to notify a credit card company when traveling? — Chase, 2026. https://www.chase.com/personal/credit-cards/education/rewards-benefits/should-you-notify-your-credit-card-company-when-traveling
- [2]Change my address — Revolut Help Centre, 2026. https://help.revolut.com/en-US/help/profile-and-plan/profile-plan/profile-settings/how-do-i-change-my-country-of-residence/
- [3]My account is being suspended by Wise — Wise Help Centre, 2026. https://wise.com/help/articles/1cBQdtgHYXIEECpCPdfOwG/my-account-is-being-suspended-by-wise
- [4]How do I verify my country of residence? — Wise Help Centre, 2026. https://wise.com/help/articles/3xConsbhr7buWkQuqDEQ5V/how-do-i-verify-my-country-of-residence
- [5]Prohibited regions — Coinbase Help, 2026. https://help.coinbase.com/en/coinbase/managing-my-account/other/prohibited-regions
- [6]Commission Delegated Regulation (EU) 2018/389 — regulatory technical standards for strong customer authentication and common and secure open standards of communication — EUR-Lex, 2018. https://eur-lex.europa.eu/eli/reg_del/2018/389/oj
- [7]EBA publishes an Opinion on the elements of strong customer authentication under PSD2 — European Banking Authority, 2019. https://www.eba.europa.eu/publications-and-media/press-releases/eba-publishes-opinion-elements-strong-customer-authentication
- [8]Can I use Smart-ID abroad? — Smart-ID, 2026. https://www.smart-id.com/help/faq/using-smart-id/can-use-smart-id-abroad/
- [9]
Bank behaviour, terms and help-centre wording verified 14 August 2026. Claims sourced to travellers rather than to institutions are labelled user-reported throughout; anything we could not establish either way is labelled unconfirmed rather than guessed at.



