Flagstar Bank, National Association
bd_5af88cb2aa8755e1 · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →7 incidents on fileFlagstar Bank, N.A. reported a cybersecurity incident involving its third-party vendor, FIS, utilizing MOVEit transfer software. The breach occurred between May 27 and May 31, 2023, and was discovered on August 8, 2023. Approximately 25,891 individuals were affected, including 22 Maine residents. The incident involved the unauthorized acquisition of personal information, including names and government identifiers. Flagstar notified affected individuals in writing starting November 6, 2023, and offered two years of credit monitoring and identity theft protection services through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
May 27, 2023
Begins
Aug 8, 2023
Discovered
Dec 27, 2023
Filed
vs. sector median
+12 wks slower
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Maine State AGbd_f45e64db77a72ae52023-12-27Verified
- California State AGbd_93d56742578abcb32023-12-15 · +12dVerified
- New Hampshire State AGbd_ba1cee24773c76652023-11-06 · +51dVerified
- Maine State AGbd_267688291d7bda9f2023-11-05 · +52dVerified
Show 6 more filings ↓Show fewer ↑up to 83d gap
- Massachusetts State AGbd_a8b93efc400ce2172023-11-05 · +52dVerified
- Indiana State AGbd_25963c4420d351012023-10-06 · +82dVerified
- Oregon State AGbd_bebe196ceda9728b2023-10-06 · +82dVerified
- Massachusetts State AGbd_25176ff42413efea2023-10-05 · +83dVerified
- Maine State AGbd_2d517ec1c38f95f82023-10-05 · +83dCandidate
- Vermont State AGbd_48a0d2a33519786f2023-10-05 · +83dVerified
Showing first 10 of 14 linked disclosures.
Filing propagation · 11 filings · 7 states
View merged incident ↗Pattern: first filing Oct 5 (MA), last Dec 27 (ME) — a 83-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 14 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.