Flagstar Bank, National Association
ent_019e22a66e0c7cdbf4d8c6389991b56f
Disclosures
25+
State AG · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,547,169
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Flagstar Bank, National Association
- Normalized
- flagstar bank national— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- SS1TRMSN6BRNMOREEV51
- SEC EDGAR CIK
- 0000910073
- Domain
- None on record
Disclosure history (newest 25)newest first
- Maine State AGas victim2023-12-27
Flagstar Bank, N.A. reported a cybersecurity incident involving its third-party vendor, FIS, utilizing MOVEit transfer software. The breach occurred between May 27 and May 31, 2023, and was discovered on August 8, 2023. Approximately 25,891 individuals were affected, including 22 Maine residents. The incident involved the unauthorized acquisition of personal information, including names and government identifiers. Flagstar notified affected individuals in writing starting November 6, 2023, and offered two years of credit monitoring and identity theft protection services through Kroll.
- Maine State AGas victim2023-12-27
Flagstar Bank, N.A. reported a data breach impacting 838,073 individuals, including 177 Maine residents, due to a security vulnerability in the MOVEit software used by its vendor, Fiserv. The breach occurred between May 27, 2023, and May 31, 2023, and was discovered on June 3, 2023. The compromised information includes names and Social Security numbers. Flagstar offered two years of credit monitoring, fraud consultation, and identity theft restoration services through Kroll to affected individuals.
- California State AGas victim2023-12-15
Flagstar Bank, N.A. notified California residents of a data breach involving its third-party vendor, Fidelity Information Services (FIS). Unauthorized actors exploited vulnerabilities in MOVEit Transfer software to access customer files between May 27 and May 31, 2023. The incident resulted in the exfiltration of personal information, including names, addresses, and potentially financial account details. Flagstar offered two years of complimentary identity monitoring through Kroll. The vendor patched the vulnerabilities and conducted a technical review.
- New Hampshire State AGas victim2023-11-06
Flagstar Bank, N.A. notified the New Hampshire Attorney General that its third-party vendor, Fidelity Information Services (FIS), experienced a security incident involving the MOVEit file transfer system. The incident, which occurred between May 27 and 31, 2023, exploited a zero-day vulnerability allowing unauthorized access to vendor files containing customer personal information. Flagstar determined 6 New Hampshire residents were affected. The vendor patched systems, and Flagstar provided 2 years of free credit monitoring to affected individuals. Notices were sent starting November 6, 2023.
- Maine State AGas victim2023-11-05
Flagstar Bank, N.A. reported an external system breach (hacking) occurring between May 27 and May 31, 2023, discovered on August 8, 2023. The incident affected 11,833 individuals, including 14 Maine residents. The breach involved the acquisition of names and personal identifiers. Flagstar Bank notified consumers in writing on November 6, 2023, and offered identity theft protection services through Kroll.
- Massachusetts State AGas victim2023-11-05
Flagstar Bank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-11-05. 48 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-10-06
Flagstar Bank, N A reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-27 and was reported on 2023-10-06. 86,243 Indiana residents were affected. 837,390 individuals affected in total.
- South Carolina State AGas victim2023-10-06
Flagstar Bank notified South Carolina and Rhode Island residents of a third-party data breach involving vendor Fiserv. Unauthorized actors exploited a vulnerability in MOVEit Transfer software between May 27-31, 2023, to access customer personal information including names and government IDs. Fiserv remediated vulnerabilities and Flagstar provided two years of identity monitoring.
- Oregon State AGas victim2023-10-06
Flagstar Bank, N.A. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-06. 837,390 individuals were affected.
- Massachusetts State AGas victim2023-10-05
Flagstar Bank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-05. 1,369 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-10-05
Flagstar Bank, N.A. reported a data breach impacting 168 Maine residents, which was part of a larger incident affecting 837,390 individuals in total. The breach, described as an external system hack, occurred between May 27 and May 31, 2023, and was discovered around June 3, 2023. The compromised information includes names and Social Security numbers. The filing notes that the breach did not occur on Flagstar's own systems, indicating a third-party vendor was involved. Affected individuals were notified on October 6, 2023, and offered two years of credit monitoring, fraud consultation, and identity theft restoration services through Kroll.
- Vermont State AGas victim2023-10-05
Flagstar Bank notified consumers that a third-party vendor, Fiserv, experienced unauthorized access to its MOVEit Transfer file transfer software between May 27 and May 31, 2023. The incident involved vulnerabilities in the MOVEit software used for payment processing and mobile banking. Customer information, including names and other personal data, was disclosed. Flagstar offered two years of identity monitoring through Kroll. The vendor patched systems and remediated vulnerabilities.
- New Hampshire State AGas victim2023-10-05
Flagstar Bank, N.A. notified the New Hampshire Attorney General on October 5, 2023, regarding a third-party vendor breach involving Fiserv's MOVEit Transfer system. Unauthorized actors exploited a zero-day vulnerability to access vendor files containing customer personal information (names, SSNs, DOBs) between May 27-31, 2023. The incident affected 278 New Hampshire residents. Flagstar's own systems were not directly compromised. Remediation included vendor patching and offering two years of complimentary identity monitoring via Kroll.
- Montana State AGas victim2023-10-05
Flagstar Bank, N.A. notified Montana residents of a data breach involving third-party vendor Fiserv. Unauthorized actors exploited a vulnerability in MOVEit Transfer software between May 27-31, 2023, accessing customer PII including names and government IDs. Fiserv patched systems and offered 2 years of Kroll identity monitoring.
- California State AGas victim2023-10-05
Flagstar Bank, N.A. notified California residents of a data breach involving its third-party vendor, Fiserv. Unauthorized actors exploited vulnerabilities in MOVEit Transfer software used by Fiserv for payment processing and mobile banking. The unauthorized activity occurred between May 27 and May 31, 2023. Customer information, including names and potentially financial account data, was disclosed. Flagstar offered two years of identity monitoring through Kroll.
- Washington State AGas victim2023-10-05
Flagstar Bank, N.A. filed a supplemental notice with the Washington AG regarding a third-party vendor incident involving Fiserv's MOVEit Transfer software. The breach, caused by a zero-day vulnerability, occurred May 27-31, 2023. It impacted 2,412 Washington residents with personal information including names and government IDs. Flagstar engaged Fiserv to investigate, patch systems, and provide two years of Kroll identity monitoring.
- California State AGas victim2023-02-24
Flagstar Bank experienced a data breach involving its third-party vendor, Accellion. An unauthorized party exploited a vulnerability in the Accellion file-sharing platform, gaining access to Flagstar's information between December 3 and December 4, 2021. Flagstar was notified of the vulnerability on January 22, 2021, and promptly took the server offline and discontinued use of the platform. Forensic investigation confirmed that certain files containing personal information were accessed and/or acquired. Flagstar engaged third-party forensic experts, notified law enforcement, and is providing two years of identity monitoring services to affected individuals through Kroll.
- Illinois State AGas victim2023-01-01
FLAGSTAR BANK, N.A filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-700). The register records the breach as discovered on May 27, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2022-09-21
Flagstar Bank notified Montana residents of a data breach involving its Accellion file-sharing vendor. The vendor's platform vulnerability was exploited by an unauthorized party, potentially exposing personal information. Flagstar took the server offline, engaged forensic experts, notified law enforcement, and offered two years of free identity monitoring via Kroll.
- Montana State AGas victim2022-09-21
Flagstar Bank notified Montana residents of a cyber incident involving unauthorized network access. Personal information (PII, government IDs) was accessed between Dec 3-4, 2021. The bank discovered the incident on June 2, 2022, engaged forensic experts, notified law enforcement, and offered two years of Kroll identity monitoring. No evidence of misuse was found.
- Washington State AGas victim2022-06-17
Flagstar Bank, FSB notified Washington AG of unauthorized network access occurring Dec 3-4, 2021. Discovered June 2, 2022, affecting 34,026 WA residents. Data included names, SSNs, DOBs, and financial account numbers. No evidence of misuse. Notices sent June 17, 2022, with 2 years of credit monitoring.
- California State AGas victim2022-06-17
Flagstar Bank, FSB experienced unauthorized access to its network between December 3 and December 4, 2021. The bank discovered the incident on June 2, 2022, after forensic investigation determined that files containing personal information were accessed and/or acquired. The bank activated its incident response plan, engaged third-party forensic experts, and notified federal law enforcement. Affected individuals are offered two years of identity monitoring through Kroll.
- Montana State AGas victim2022-06-17
Flagstar Bank notified Montana residents of a cyber incident involving unauthorized network access. The breach occurred between Dec 3-4, 2021, and was discovered on June 2, 2022. Personal information including names and government IDs was accessed. Flagstar engaged forensic experts, notified law enforcement, and provided two years of free identity monitoring via Kroll.
- Oregon State AGas victim2022-06-17
Flagstar Bank, FSB reported a data breach to the Oregon Attorney General. The breach was reported on 2022-06-17. The breach occurred during 12/3/2021 - 12/4/2021. The breach was discovered on 6/2/2022. 1,547,169 individuals were affected. Notice was sent on 6/17/2022.
- Maine State AGas victim2022-06-17
Flagstar Bank, FSB reported an external system breach that occurred on December 3rd and 4th, 2021, and was discovered on June 2nd, 2022. The breach compromised the Social Security Numbers of 1,547,169 individuals, including 1,028 Maine residents. In response, Flagstar offered two years of credit monitoring and identity repair services through Kroll.
Supply-chain cascadesreviewed and confirmed
- Flagstar Bank, National Association’s filing is one of at least 10 in the FISERV, INC. supply-chain incident (2023).
- Flagstar Bank, National Association’s filing is one of at least 12 in the Accellion supply-chain incident (2021).