HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Flagstar Bank, National Association
bd_f45e64db77a72ae5 · schema v1 · pii pii-v1
Full breach record for Flagstar Bank, National Association →Flagstar Bank, N.A. reported a data breach impacting 838,073 individuals, including 177 Maine residents, due to a security vulnerability in the MOVEit software used by its vendor, Fiserv. The breach occurred between May 27, 2023, and May 31, 2023, and was discovered on June 3, 2023. The compromised information includes names and Social Security numbers. Flagstar offered two years of credit monitoring, fraud consultation, and identity theft restoration services through Kroll to affected individuals.
Maine clockDiscovered Jun 3, 2023 → Filed with AG Dec 27, 2023207d ✗ ME AG >90d30 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 12 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_5af88cb2aa8755e1Maine State AGfiled 2023-12-27Verified
- bd_93d56742578abcb3California State AGfiled 2023-12-15(12d gap)Verified
- bd_ba1cee24773c7665New Hampshire State AGfiled 2023-11-06(51d gap)Verified
- bd_267688291d7bda9fMaine State AGfiled 2023-11-05(52d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 83d gap
- bd_bebe196ceda9728bOregon State AGfiled 2023-10-06(82d gap)Verified
- bd_2d517ec1c38f95f8Maine State AGfiled 2023-10-05(83d gap)Candidate
- bd_48a0d2a33519786fVermont State AGfiled 2023-10-05(83d gap)Verified
- bd_6e65b118877be0c8New Hampshire State AGfiled 2023-10-05(83d gap)Verified
- bd_9e2f8b843a8d75b2Montana State AGfiled 2023-10-05(83d gap)Candidate
- bd_d88cc15ddbaabe7dCalifornia State AGfiled 2023-10-05(83d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/4c2ddf4c-8aa6-4923-ab98-dc5d0fb2a1e2.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 27, 2023
- Raw hash
- 2bd38ea91f19e4adfa9e5a625b76c9b3127f3af769a17ce47d69ea354cb9e865
Reporting entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Victim entity
- Name
- Flagstar Bank, National Associationnorm: flagstar bank national
Incident
- Discovered
- Jun 3, 2023
- Materiality determined
- —
- Notification sent
- Oct 6, 2023
- Affected individuals
- 177
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
Compliance
- Time to disclose
- 30 weeks(207 days from discovery to filing)
- Compliance flags
- ME AG >90d · 207dME resident >60d · 125d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 3, 2023→ Filed with AG: Dec 27, 2023207d 90 days ME AG >90d Maine Discovered: Jun 3, 2023→ Notified: Oct 6, 2023125d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.