HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Flagstar Bank, National Association
bd_48a0d2a33519786f · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank notified Vermont and Rhode Island residents of a data breach involving third-party vendor Fiserv's use of Progress Software MOVEit Transfer. Unauthorized actors accessed files containing customer PII (names, SSNs, DOBs) between May 27-31, 2023. Flagstar engaged forensic investigation, patched systems, and provided two years of Kroll identity monitoring. 286 Rhode Island residents were explicitly identified as impacted.
Vermont clock✗ VT AG >45 bday19 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 12 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_2d517ec1c38f95f8Maine State AGfiled 2023-10-05Candidate
- bd_6e65b118877be0c8New Hampshire State AGfiled 2023-10-05Verified
- bd_9e2f8b843a8d75b2Montana State AGfiled 2023-10-05Candidate
- bd_d88cc15ddbaabe7dCalifornia State AGfiled 2023-10-05Verified
Show 6 more filings ↓Show fewer ↑up to 83d gap
- bd_bebe196ceda9728bOregon State AGfiled 2023-10-06(1d gap)Verified
- bd_267688291d7bda9fMaine State AGfiled 2023-11-05(31d gap)Verified
- bd_ba1cee24773c7665New Hampshire State AGfiled 2023-11-06(32d gap)Verified
- bd_93d56742578abcb3California State AGfiled 2023-12-15(71d gap)Verified
- bd_5af88cb2aa8755e1Maine State AGfiled 2023-12-27(83d gap)Verified
- bd_f45e64db77a72ae5Maine State AGfiled 2023-12-27(83d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-05-flagstar-bank-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2023
- Raw hash
- 1495764a565647d116c349580c654935e1e35e8c7cfecd0681f335f823e3fc9b
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- May 27, 2023
- Materiality determined
- Oct 5, 2023
- Notification sent
- Oct 5, 2023
- Affected individuals
- 286
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulatory bodies as required
- Initial access
- supply_chain
Compliance
- Time to disclose
- 19 weeks(131 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.