Flagstar 2021 data breach victims can claim up to $25,000 before August 11

2 hours ago 1
Chattythat Icon

Flagstar’s 2021 data breaches affected nearly 2.2 million people; eligible Americans have until August 11 to claim documented losses up to $25,000 from a proposed $31.5 million settlement

Flagstar Bank has agreed to pay $31.5 million to settle a class action lawsuit over two cyberattacks in 2021.

Millions of Flagstar Bank customers who were affected by two cyberattacks in 2021 could be eligible for compensation under a class action settlement. The American bank has agreed to pay $31.5 million to settle claims linked to the data breaches, although it continues to deny any wrongdoing.The lawsuits were filed after hackers accessed sensitive personal information during the cyberattacks. Customers claimed that the bank failed to properly protect their personal information and did not notify them about the breaches quickly enough. Now, the bank has decided not to with a lengthy court battle and agreed to resolve the case through a settlement reached during mediation.People who received a notice saying their information was affected can now submit claims for compensation.

According to New York Post, depending on the type of losses they experienced and the documents they provide, customers could receive payments ranging from around $60 to as much as $25,000. The deadline to submit a claim is August 11, 2026.

2021 breaches impacted millions

The legal case centres on two separate cyberattacks that took place in 2021. The first attack happened in January, when cyber criminals accessed sensitive information belonging to more than 1.4 million Flagstar customers.

According to a government document, a threat actor gained unauthorised access to Flagstar's remote access platform, known as its Citrix environment. The attackers deployed ransomware that encrypted about 30% of the bank's workstations and servers and stole customer data, including personally identifiable information (PII).The breach also disrupted Flagstar's mortgage operations, affected its website, mobile applications and customer call centre, and forced the bank to rebuild hundreds of servers and reset thousands of employee passwords.Later that year, in December, the bank suffered another cyberattack that affected more than 1.5 million people.According to Cybersecurity Dive, Flagstar was also affected by the 2023 breach of the MOVEit file transfer system, which exposed the data of about 837,390 of its customers.

$31.5 million settlement fund

Under the settlement, Flagstar will create a $31.5 million fund to compensate eligible customers. The amount each person receives will depend on the type of claim submitted, the supporting documents provided and the total number of valid claims approved.Some customers may receive significantly higher payments than others. Those who can provide documents showing financial losses linked to the 2021 data breaches may qualify for payments of up to $25,000. These losses may include money lost because of fraud, expenses related to identity theft or the cost of credit monitoring services that became necessary after the breaches.

Attackers deployed ransomware that encrypted about 30% of the bank's workstations.<br>

Attackers deployed ransomware that encrypted about 30% of the bank's workstations.

Customers who do not have documented financial losses may still qualify for a payment.

The settlement estimates these residual payments at around $60, although they could be as high as $599 depending on how much money remains in the settlement fund after approved claims, legal costs and other expenses have been paid.The settlement also provides a separate benefit for eligible customers in California. Those who can show they were affected by the data breaches and submit a valid claim may receive payments of up to $100.The final amount paid to each claimant will depend on the settlement terms and the number of approved claims. Customers must meet the eligibility requirements and complete the claims process before any payment can be issued.

Free credit monitoring

Eligible customers can also choose free credit monitoring as part of the settlement apart from seeking cash compensation. The package includes monitoring from all three major credit bureaus, identity theft insurance worth up to $1 million, dark web monitoring, fully managed identity restoration, member advisory services and lost wallet assistance.These services are intended to help customers monitor their personal information and respond if it is misused. People who are submitting claims can request these services through the claim form if they are eligible under the settlement.

Who can file claim

People who received a notice saying that their personal information was affected by either of the 2021 data breaches are eligible to submit a claim. According to the settlement, these notices were sent to settlement class members either electronically or through direct mail.Anyone who believes they should have been included but did not receive a notice can contact the Settlement Administrator to check whether they are eligible.Customers who wish to receive compensation or free credit monitoring must submit a valid claim by August 11, 2026. The settlement website provides claim forms, answers to frequently asked questions, information about eligibility requirements and details of the benefits available under the agreement.

Read Entire Article