Flagstar Bank, National Association
bd_93d56742578abcb3 · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank, N.A. notified California residents of a data breach involving its third-party vendor, Fidelity Information Services (FIS). Unauthorized actors exploited vulnerabilities in MOVEit Transfer software to access customer files between May 27 and May 31, 2023. The incident resulted in the exfiltration of personal information, including names, addresses, and potentially financial account details. Flagstar offered two years of complimentary identity monitoring through Kroll. The vendor patched the vulnerabilities and conducted a technical review.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_5af88cb2aa8755e1Maine State AGfiled 2023-12-27(12d gap)Verified
- bd_f45e64db77a72ae5Maine State AGfiled 2023-12-27(12d gap)Verified
- bd_ba1cee24773c7665New Hampshire State AGfiled 2023-11-06(39d gap)Verified
- bd_267688291d7bda9fMaine State AGfiled 2023-11-05(40d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 71d gap
- bd_bebe196ceda9728bOregon State AGfiled 2023-10-06(70d gap)Verified
- bd_2d517ec1c38f95f8Maine State AGfiled 2023-10-05(71d gap)Candidate
- bd_48a0d2a33519786fVermont State AGfiled 2023-10-05(71d gap)Verified
- bd_6e65b118877be0c8New Hampshire State AGfiled 2023-10-05(71d gap)Verified
- bd_9e2f8b843a8d75b2Montana State AGfiled 2023-10-05(71d gap)Candidate
- bd_d88cc15ddbaabe7dCalifornia State AGfiled 2023-10-05(71d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578019
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2023
- Raw hash
- 8150f70eadacc06aab3ada8584ed988f5b45d4a959189dcafb06a7a9a122dcd8
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified regulatory bodies as required
- Third party
- via Fidelity Information Services, LLC
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.