
Michigan-based Flagstar Bank suffered a significant Data breach as a result of the exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer web application.In a recent notice of data breach filed with the Maine Attorney General’s office, Flagstar Bank said that Fiserv, a third-party vendor the bank uses for payment processing and mobile banking purposes, used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application to access its users’ data.Soon after being notified about the exploitation involving the file transfer application, Fiserv launched an internal investigation to understand the scope of the data security incident. The investigation revealed that “unauthorised activity in the MOVEit Transfer environment occurred between May 27 and 31, 2023, which was before the existence of this vulnerability was publicly disclosed.”“The vulnerability discovered in MOVEit did not involve any of Flagstar Bank’s systems and did not impact our ability to service our customers,” the financial institution said.The files accessed by the Clop ransomware group, the hacker group responsible for the cyber security incident, contained the sensitive personal information of Flagstar Bank’s customers. The compromised data includes names and other personal identifiers including Social Security Numbers.The filing with the Attorney General’s Office also confirmed that at least 837,390 individuals were affected by the data breach.“Upon learning of this incident, Flagstar took immediate action to ensure that our vendor had launched a comprehensive investigation, identified individuals affected and notified regulatory bodies as required.“To help prevent something like this happening again our vendor has, through their service provider, remediated all technical vulnerabilities and patched systems in accordance with the MOVEit software provider’s guidelines.“Our vendor’s service provider also mobilised a technical response team to examine the relevant MOVEit systems and ensure that there were no further vulnerabilities,” the bank added.Flagstar Bank is providing two years of complementary credit monitoring, fraud consultation and identity theft restoration service through Kroll to all affected individuals whose data was compromised in the security incident.In June, Flagstar Bank disclosed another security incident that took place between December 3 and December 4, 2022. The breach was discovered on June 2 this year, exactly six months after it occurred.Following an extensive investigation, the bank identified that a threat actor gained unauthorised access to its network and accessed certain files containing customer details, including the names and social security numbers of its customers. Based on the information provided to the Office of the Attorney General of Maine, the security incident affected 1,547,169 people in the United States.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543