Cyber Incident Victim: Flagstar Bank FSB
Timeline
Summary
Flagstar Bank experienced two separate intrusions that exposed the personal information of more than 1.4 million customers. The institution denied any wrongdoing but agreed to a $31.5 million settlement to avoid prolonged litigation. About 2.19 million people are included in the settlement class, eligible for reimbursement of documented losses up to $25,000, a residual cash payment of roughly $60, and three years of three‑bureau credit monitoring with $1 million in identity theft insurance, dark web monitoring and restoration services.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In January 2021, hackers allegedly gained access to the personal information of more than 1.4 million Flagstar Bank customers. A second breach occurred in December of the same year, affecting additional customer data. Plaintiffs in a subsequent complaint alleged that Flagstar Bank failed to implement adequate security measures to protect customer information and delayed notifying affected individuals about both incidents. The bank, headquartered in Hicksville, New York, denied any wrongdoing in response to the allegations.

To resolve the litigation, Flagstar Bank agreed to a settlement valued at $31.5 million without admitting liability. The settlement class comprises approximately 2.19 million individuals who were impacted by the two breaches. Eligible class members may submit a claim for reimbursement of documented losses resulting from the breaches, with a maximum payment of $25,000 per claimant. Those who do not wish to pursue documented loss reimbursement may receive a pro rata cash payment of about $60, subject to adjustment based on the total number of valid claims and associated legal costs.
The settlement also provides class members with three years of three‑bureau credit monitoring services from IDX, accompanied by $1 million in identity theft insurance, dark web monitoring, and identity restoration services. Claimants who were California residents at the time of the breaches may be eligible for an additional $100 payment under the California Consumer Privacy Act. The deadline to submit a claim is August 11, 2026, while the final date to object to or request exclusion from the settlement was June 29, 2026. Flagstar Bank stated that the settlement was reached to avoid the prospect of prolonged litigation.
