Flagstar Bank, National Association
bd_ba1cee24773c7665 · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank, N.A. notified the New Hampshire Attorney General that its third-party vendor, Fidelity Information Services (FIS), experienced a security incident involving the MOVEit file transfer system. The incident, which occurred between May 27 and 31, 2023, exploited a zero-day vulnerability allowing unauthorized access to vendor files containing customer personal information. Flagstar determined 6 New Hampshire residents were affected. The vendor patched systems, and Flagstar provided 2 years of free credit monitoring to affected individuals. Notices were sent starting November 6, 2023.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_267688291d7bda9fMaine State AGfiled 2023-11-05(1d gap)Verified
- bd_bebe196ceda9728bOregon State AGfiled 2023-10-06(31d gap)Verified
- bd_2d517ec1c38f95f8Maine State AGfiled 2023-10-05(32d gap)Candidate
- bd_48a0d2a33519786fVermont State AGfiled 2023-10-05(32d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 51d gap
- bd_6e65b118877be0c8New Hampshire State AGfiled 2023-10-05(32d gap)Verified
- bd_9e2f8b843a8d75b2Montana State AGfiled 2023-10-05(32d gap)Candidate
- bd_d88cc15ddbaabe7dCalifornia State AGfiled 2023-10-05(32d gap)Verified
- bd_93d56742578abcb3California State AGfiled 2023-12-15(39d gap)Verified
- bd_5af88cb2aa8755e1Maine State AGfiled 2023-12-27(51d gap)Verified
- bd_f45e64db77a72ae5Maine State AGfiled 2023-12-27(51d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/flagstar-bank-20231106.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 6, 2023
- Raw hash
- 6782ca2539dce640cb0369862651436cbb6add0e80383026dc0a2bcdf7a4b9bc
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- Nov 1, 2023
- Materiality determined
- —
- Notification sent
- Nov 6, 2023
- Affected individuals
- 6
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Vendor notified regulatory bodies as requiredFlagstar reported the matter to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.