Flagstar Bank, National Association
ent_019e22a66e0c7cdbf4d8c6389991b56f
Disclosures
23
State AG · 7 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,547,169
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Flagstar Bank, National Association
- Normalized
- flagstar bank national— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- SS1TRMSN6BRNMOREEV51
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (23)newest first
- 🦞Maine State AGas victim2023-12-27
Flagstar Bank, N.A. reported a cybersecurity incident involving its third-party vendor, FIS, utilizing MOVEit transfer software. The breach occurred between May 27 and May 31, 2023, and was discovered on August 8, 2023. Approximately 25,891 individuals were affected, including 22 Maine residents. The incident involved the unauthorized acquisition of personal information, including names and government identifiers. Flagstar notified affected individuals in writing starting November 6, 2023, and offered two years of credit monitoring and identity theft protection services through Kroll.
- 🦞Maine State AGas victim2023-12-27
Flagstar Bank, N.A. reported a data breach impacting 838,073 individuals, including 177 Maine residents, due to a security vulnerability in the MOVEit software used by its vendor, Fiserv. The breach occurred between May 27, 2023, and May 31, 2023, and was discovered on June 3, 2023. The compromised information includes names and Social Security numbers. Flagstar offered two years of credit monitoring, fraud consultation, and identity theft restoration services through Kroll to affected individuals.
- 🐻California State AGas victim2023-12-15
Flagstar Bank, N.A. notified California residents of a data breach involving its third-party vendor, Fidelity Information Services (FIS). Unauthorized actors exploited vulnerabilities in MOVEit Transfer software to access customer files between May 27 and May 31, 2023. The incident resulted in the exfiltration of personal information, including names, addresses, and potentially financial account details. Flagstar offered two years of complimentary identity monitoring through Kroll. The vendor patched the vulnerabilities and conducted a technical review.
- ⛰️New Hampshire State AGas victim2023-11-06
Flagstar Bank, N.A. notified the New Hampshire Attorney General that its third-party vendor, Fidelity Information Services (FIS), experienced a security incident involving the MOVEit file transfer system. The incident, which occurred between May 27 and 31, 2023, exploited a zero-day vulnerability allowing unauthorized access to vendor files containing customer personal information. Flagstar determined 6 New Hampshire residents were affected. The vendor patched systems, and Flagstar provided 2 years of free credit monitoring to affected individuals. Notices were sent starting November 6, 2023.
- 🦞Maine State AGas victim2023-11-05
Flagstar Bank, N.A. reported an external system breach (hacking) occurring between May 27 and May 31, 2023, discovered on August 8, 2023. The incident affected 11,833 individuals, including 14 Maine residents. The breach involved the acquisition of names and personal identifiers. Flagstar Bank notified consumers in writing on November 6, 2023, and offered identity theft protection services through Kroll.
- 🦫Oregon State AGas victim2023-10-06
Flagstar Bank, N.A. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-06. 837,390 individuals were affected.
- 🦞Maine State AGas victim2023-10-05
Flagstar Bank, N.A. reported a data breach impacting 168 Maine residents, which was part of a larger incident affecting 837,390 individuals in total. The breach, described as an external system hack, occurred between May 27 and May 31, 2023, and was discovered around June 3, 2023. The compromised information includes names and Social Security numbers. The filing notes that the breach did not occur on Flagstar's own systems, indicating a third-party vendor was involved. Affected individuals were notified on October 6, 2023, and offered two years of credit monitoring, fraud consultation, and identity theft restoration services through Kroll.
- 🍁Vermont State AGas victim2023-10-05
Flagstar Bank notified Vermont and Rhode Island residents of a data breach involving third-party vendor Fiserv's use of Progress Software MOVEit Transfer. Unauthorized actors accessed files containing customer PII (names, SSNs, DOBs) between May 27-31, 2023. Flagstar engaged forensic investigation, patched systems, and provided two years of Kroll identity monitoring. 286 Rhode Island residents were explicitly identified as impacted.
- ⛰️New Hampshire State AGas victim2023-10-05
Flagstar Bank, N.A. notified the New Hampshire Attorney General on October 5, 2023, regarding a third-party vendor breach involving Fiserv's MOVEit Transfer system. Unauthorized actors exploited a zero-day vulnerability to access vendor files containing customer personal information (names, SSNs, DOBs) between May 27-31, 2023. The incident affected 278 New Hampshire residents. Flagstar's own systems were not directly compromised. Remediation included vendor patching and offering two years of complimentary identity monitoring via Kroll.
- 🦬Montana State AGas victim2023-10-05
Flagstar Bank, N.A. reported a data breach to the Montana Attorney General. The breach was reported on 2023-10-05. The breach occurred from 5/27/2023 to 5/31/2023. 304 Montana residents were affected.
- 🐻California State AGas victim2023-10-05
Flagstar Bank, N.A. notified California residents of a data breach involving its third-party vendor, Fiserv. Unauthorized actors exploited vulnerabilities in MOVEit Transfer software used by Fiserv for payment processing and mobile banking. The unauthorized activity occurred between May 27 and May 31, 2023. Customer information, including names and potentially financial account data, was disclosed. Flagstar offered two years of identity monitoring through Kroll.
- 🌲Washington State AGas victim2023-10-05
Flagstar Bank, NA, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-08-03 and filed notice on 2023-10-05. 2,412 Washington residents were affected. 63 days elapsed between awareness and notification. 68 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2023-02-24
Flagstar Bank experienced a data breach involving its third-party vendor, Accellion. An unauthorized party exploited a vulnerability in the Accellion file-sharing platform, gaining access to Flagstar's information between December 3 and December 4, 2021. Flagstar was notified of the vulnerability on January 22, 2021, and promptly took the server offline and discontinued use of the platform. Forensic investigation confirmed that certain files containing personal information were accessed and/or acquired. Flagstar engaged third-party forensic experts, notified law enforcement, and is providing two years of identity monitoring services to affected individuals through Kroll.
- 🌲Washington State AGas victim2022-06-17
Flagstar Bank, FSB, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2021-12-03 and filed notice on 2022-06-17. 34,026 Washington residents were affected. 196 days elapsed between awareness and notification. 0 days to identify the breach. 1 days to contain the breach.
- 🐻California State AGas victim2022-06-17
Flagstar Bank, FSB reported a cybersecurity incident involving unauthorized access to its network occurring between December 3 and 4, 2021. The breach was discovered on June 2, 2022, after forensic investigation. Flagstar activated its incident response plan, engaged external forensic experts, and reported the matter to federal law enforcement. No evidence of misuse was found, but impacted individuals were offered two years of complimentary identity monitoring through Kroll.
- 🦬Montana State AGas victim2022-06-17
Flagstar Bank reported a data breach to the Montana Attorney General. The breach was reported on 2022-06-17. The breach occurred from 12/3/2021 to 12/4/2021. 5,398 Montana residents were affected.
- 🦫Oregon State AGas victim2022-06-17
Flagstar Bank, FSB reported a data breach to the Oregon Attorney General. The breach was reported on 2022-06-17. The breach occurred during 12/3/2021 - 12/4/2021. The breach was discovered on 6/2/2022. 1,547,169 individuals were affected. Notice was sent on 6/17/2022.
- 🦞Maine State AGas victim2022-06-17
Flagstar Bank, FSB reported an external system breach that occurred on December 3rd and 4th, 2021, and was discovered on June 2nd, 2022. The breach compromised the Social Security Numbers of 1,547,169 individuals, including 1,028 Maine residents. In response, Flagstar offered two years of credit monitoring and identity repair services through Kroll.
- 🐻California State AGas victim2021-03-15
Flagstar Bank, FSB disclosed a data breach involving its third-party file-sharing vendor, Accellion. The vulnerability was identified on January 22, 2021. Unauthorized parties accessed documents containing customer personal information, including names, Social Security numbers, and dates of birth. Flagstar took the server offline, engaged forensic experts, notified law enforcement, and offered two years of free identity monitoring via Kroll.
- 🦫Oregon State AGas victim2021-03-15
Flagstar Bank, FSB reported a data breach to the Oregon Attorney General. The breach was reported on 2021-03-15. The breach occurred during 1/20/2021 - 1/22/2021. The breach was discovered on 1/24/2021. 1,465,002 individuals were affected. Notice was sent on 3/15/2021.
- 🦬Montana State AGas victim2021-03-15
Flagstar Bank, FSB reported a data breach to the Montana Attorney General. The breach was reported on 2021-03-15. The breach occurred on 1/22/2021. 7,245 Montana residents were affected.
- 🦞Maine State AGas victim2021-03-15
Flagstar Bank, FSB, a financial services company, reported a data breach that occurred between January 20, 2021, and January 22, 2021. The breach, discovered on January 24, 2021, was a result of an external system hack. The incident affected 2,314 Maine residents, compromising their names and Social Security numbers. In response, the bank offered credit monitoring and identity repair services through Kroll.
- 🌲Washington State AGas victim2021-03-15
Flagstar Bank, FSB, a finance sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-01-24 and filed notice on 2021-03-15. 61,006 Washington residents were affected. 50 days elapsed between awareness and notification.