Flagstar Bank, National Association
bd_5af88cb2aa8755e1 · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank, N.A. reported a cybersecurity incident involving its third-party vendor, FIS, utilizing MOVEit transfer software. The breach occurred between May 27 and May 31, 2023, and was discovered on August 8, 2023. Approximately 25,891 individuals were affected, including 22 Maine residents. The incident involved the unauthorized acquisition of personal information, including names and government identifiers. Flagstar notified affected individuals in writing starting November 6, 2023, and offered two years of credit monitoring and identity theft protection services through Kroll.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_f45e64db77a72ae5Maine State AGfiled 2023-12-27Verified
- bd_93d56742578abcb3California State AGfiled 2023-12-15(12d gap)Verified
- bd_ba1cee24773c7665New Hampshire State AGfiled 2023-11-06(51d gap)Verified
- bd_267688291d7bda9fMaine State AGfiled 2023-11-05(52d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 83d gap
- bd_bebe196ceda9728bOregon State AGfiled 2023-10-06(82d gap)Verified
- bd_2d517ec1c38f95f8Maine State AGfiled 2023-10-05(83d gap)Candidate
- bd_48a0d2a33519786fVermont State AGfiled 2023-10-05(83d gap)Verified
- bd_6e65b118877be0c8New Hampshire State AGfiled 2023-10-05(83d gap)Verified
- bd_9e2f8b843a8d75b2Montana State AGfiled 2023-10-05(83d gap)Candidate
- bd_d88cc15ddbaabe7dCalifornia State AGfiled 2023-10-05(83d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1597494e-33db-450f-9959-357d0f2eb461.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 27, 2023
- Raw hash
- 139f9e3bb8da74f6a4e64f308212adf5da1b01feee8e402cfb91f996a6fb41bb
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- Aug 8, 2023
- Materiality determined
- —
- Notification sent
- Nov 6, 2023
- Affected individuals
- 25,891
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- ME AG >90d · 141dME resident >60d · 90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 8, 2023→ Filed with AG: Dec 27, 2023141d 90 days ME AG >90d Maine Discovered: Aug 8, 2023→ Notified: Nov 6, 202390d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.