HackingData ExfiltratedPIIIDENTITY_BASICLowContained
Flagstar Bank, National Association
bd_47783abf983cb858 · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank, FSB reported a cybersecurity incident involving unauthorized access to its network occurring between December 3 and 4, 2021. The breach was discovered on June 2, 2022, after forensic investigation. Flagstar activated its incident response plan, engaged external forensic experts, and reported the matter to federal law enforcement. No evidence of misuse was found, but impacted individuals were offered two years of complimentary identity monitoring through Kroll.
California clockDiscovered Jun 2, 2022 → Notified Jun 17, 202215d ✓ CA 60-day OK15 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_133f88bc5edc2e2aWashington State AGfiled 2022-06-17Candidate
- bd_57ba7d3507776a33Montana State AGfiled 2022-06-17Verified
- bd_876b162fd6c79360Oregon State AGfiled 2022-06-17Verified by operator
- bd_92f81614d7dc142aMaine State AGfiled 2022-06-17Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554369
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 17, 2022
- Raw hash
- dc0b3a4194e7bfc0c896ba9baf0b99204bc8870bf9c2583503e135770d7d478d
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- Jun 2, 2022
- Materiality determined
- —
- Notification sent
- Jun 17, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- reported the matter to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 15d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 2, 2022→ Notified: Jun 17, 202215d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.