Flagstar Bank told 837,000 customers their data was taken in Fiserv MOVEit breach
- Organization
- Flagstar Bank
- Exploit
- Third-Party Data Breach
- Industry
- Financial Services
Flagstar Bank notified 837,390 customers in the United States that their personal information had been taken in a breach at one of its service providers. The Michigan-based bank, then owned by New York Community Bancorp, said the data was exposed at Fiserv, which supplies payment processing and mobile banking services to Flagstar and to hundreds of other financial institutions.
Fiserv was one of many organizations caught in the mass exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer product. Flagstar said the unauthorized activity at Fiserv took place between May 27 and May 31, 2023, before the flaw was publicly disclosed. The Clop extortion group ran the campaign, which reached thousands of organizations and tens of millions of people.
Flagstar filed a breach notice with the Maine Attorney General on October 6, 2023. The reported data elements included customer names and Social Security numbers. The bank said none of its own systems were involved and that its ability to service customer accounts was not affected.
Flagstar said it acted promptly once it learned of the breach, and that its vendor investigated, identified the affected individuals, notified regulators and remediated the vulnerability. Affected customers were offered two years of identity monitoring through Kroll. It was the third incident to expose Flagstar customer data since 2021, after a 2021 compromise of an Accellion file transfer server by Clop and a corporate network intrusion disclosed in 2022 that affected about 1.5 million people.