HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Flagstar Bank, National Association
bd_d88cc15ddbaabe7d · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank, N.A. notified California residents of a data breach involving its third-party vendor, Fiserv. Unauthorized actors exploited vulnerabilities in MOVEit Transfer software used by Fiserv for payment processing and mobile banking. The unauthorized activity occurred between May 27 and May 31, 2023. Customer information, including names and potentially financial account data, was disclosed. Flagstar offered two years of identity monitoring through Kroll.
This filing is one of 12 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_2d517ec1c38f95f8Maine State AGfiled 2023-10-05Candidate
- bd_48a0d2a33519786fVermont State AGfiled 2023-10-05Verified
- bd_6e65b118877be0c8New Hampshire State AGfiled 2023-10-05Verified
- bd_9e2f8b843a8d75b2Montana State AGfiled 2023-10-05Candidate
Show 6 more filings ↓Show fewer ↑up to 83d gap
- bd_bebe196ceda9728bOregon State AGfiled 2023-10-06(1d gap)Verified
- bd_267688291d7bda9fMaine State AGfiled 2023-11-05(31d gap)Verified
- bd_ba1cee24773c7665New Hampshire State AGfiled 2023-11-06(32d gap)Verified
- bd_93d56742578abcb3California State AGfiled 2023-12-15(71d gap)Verified
- bd_5af88cb2aa8755e1Maine State AGfiled 2023-12-27(83d gap)Verified
- bd_f45e64db77a72ae5Maine State AGfiled 2023-12-27(83d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574719
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2023
- Raw hash
- d3f4d8910c112923a269b79951c92e6bf3c112263adfc7dfc3ff89a2a3c24012
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Fiserv
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.