Menu
Browse

Cyber Incident Victim: Flagstar Bank FSB

Date

Dec 2021

Location

United States of America

Status

Historical

Updated

2026-08-09 07:39

Timeline
Occurred
Jan 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

Flagstar Bank experienced two separate intrusions that exposed the personal information of more than 1.4 million customers. The institution denied any wrongdoing but agreed to a $31.5 million settlement to avoid prolonged litigation. About 2.19 million people are included in the settlement class, eligible for reimbursement of documented losses up to $25,000, a residual cash payment of roughly $60, and three years of three‑bureau credit monitoring with $1 million in identity theft insurance, dark web monitoring and restoration services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

In January 2021, hackers allegedly gained access to the personal information of more than 1.4 million Flagstar Bank customers. A second breach occurred in December of the same year, affecting additional customer data. Plaintiffs in a subsequent complaint alleged that Flagstar Bank failed to implement adequate security measures to protect customer information and delayed notifying affected individuals about both incidents. The bank, headquartered in Hicksville, New York, denied any wrongdoing in response to the allegations.

Cyber Incident Image

To resolve the litigation, Flagstar Bank agreed to a settlement valued at $31.5 million without admitting liability. The settlement class comprises approximately 2.19 million individuals who were impacted by the two breaches. Eligible class members may submit a claim for reimbursement of documented losses resulting from the breaches, with a maximum payment of $25,000 per claimant. Those who do not wish to pursue documented loss reimbursement may receive a pro rata cash payment of about $60, subject to adjustment based on the total number of valid claims and associated legal costs.

The settlement also provides class members with three years of three‑bureau credit monitoring services from IDX, accompanied by $1 million in identity theft insurance, dark web monitoring, and identity restoration services. Claimants who were California residents at the time of the breaches may be eligible for an additional $100 payment under the California Consumer Privacy Act. The deadline to submit a claim is August 11, 2026, while the final date to object to or request exclusion from the settlement was June 29, 2026. Flagstar Bank stated that the settlement was reached to avoid the prospect of prolonged litigation.

Sources
Sources available to members
1 source