Flagstar Bank, National Association
bd_6e65b118877be0c8 · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank, N.A. notified the New Hampshire Attorney General on October 5, 2023, regarding a third-party vendor breach involving Fiserv's MOVEit Transfer system. Unauthorized actors exploited a zero-day vulnerability to access vendor files containing customer personal information (names, SSNs, DOBs) between May 27-31, 2023. The incident affected 278 New Hampshire residents. Flagstar's own systems were not directly compromised. Remediation included vendor patching and offering two years of complimentary identity monitoring via Kroll.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_2d517ec1c38f95f8Maine State AGfiled 2023-10-05Candidate
- bd_48a0d2a33519786fVermont State AGfiled 2023-10-05Verified
- bd_9e2f8b843a8d75b2Montana State AGfiled 2023-10-05Candidate
- bd_d88cc15ddbaabe7dCalifornia State AGfiled 2023-10-05Verified
Show 6 more filings ↓Show fewer ↑up to 83d gap
- bd_bebe196ceda9728bOregon State AGfiled 2023-10-06(1d gap)Verified
- bd_267688291d7bda9fMaine State AGfiled 2023-11-05(31d gap)Verified
- bd_ba1cee24773c7665New Hampshire State AGfiled 2023-11-06(32d gap)Verified
- bd_93d56742578abcb3California State AGfiled 2023-12-15(71d gap)Verified
- bd_5af88cb2aa8755e1Maine State AGfiled 2023-12-27(83d gap)Verified
- bd_f45e64db77a72ae5Maine State AGfiled 2023-12-27(83d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/flagstar-bank-20231005.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2023
- Raw hash
- 3807a6af68acaebf73cca6d356dccf205583fd0cbb37f3a6a5c75d186d6f37aa
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Oct 5, 2023
- Affected individuals
- 278
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General, Consumer Protection & Antitrust Bureau
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.