DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitData MishandlingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Government IDHighContained

Flagstar Bank, National Association

bd_99bd7b6b31840112 · schema v1 · pii pii-v1

Severity

High

Discovered

Jan 22, 2021

Filed

Mar 15, 2021

To disclose

7 weeks

Affected

7,245state residents only

Linked

8 filings

Confidence

67%
Full breach record for Flagstar Bank, National Association →7 incidents on file

Flagstar Bank, FSB notified Montana residents of a data breach involving its third-party file-sharing vendor, Accellion. The vendor's platform vulnerability was exploited, leading to unauthorized access of customer personal information. Flagstar took the server offline, engaged forensic experts, and notified law enforcement. Affected individuals were offered two years of identity monitoring services.

Incident timeline

discovery → filing · 7 weeks / 52 days

Jan 22, 2021

Discovered

Mar 15, 2021

Filed

vs. sector median

3 wks faster

This filing is one of 8 filings about the same incident.View merged incident
Part of Accellion supply-chain incident (2021) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filings ↓up to 3d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.