Desk live·
ForensicPost
Breaches/Finance/File 22-0617

Flagstar Bank Told 1,547,169 Customers Six Months After a Two-Day Intrusion

Flagstar Bank places the intrusion on 3–4 December 2021. The investigation concluded on 2 June 2022 and customers were written to on the 17th — 1,547,169 of them, social security numbers included.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFlagstar Bank
ActorUnattributed
D. Kennedy10 min readConfidence: high2 sources reviewed

Flagstar Bank disclosed a breach affecting 1,547,169 customers, reporting the intrusion as having occurred on 3 and 4 December 2021. The investigation concluded on 2 June 2022, and customers were notified from 17 June. Names, other personal information and social security numbers were accessed. Two years of identity monitoring were offered.

Reporting at the time noted this as the third breach disclosed by the bank in two years. The company stated it had no evidence that personal information had been misused.

Six Months, Of Which The Investigation Was Most

The interval from intrusion to notification is roughly six and a half months, and it decomposes usefully: about six months to conclude an investigation, then a fortnight to write to people.

We filed this interval constantly — 289 days at 26-0721b, four months at 22-0404, ten months from detection to disclosure at 23-0808b — and argues the clock that matters to an affected person starts when the data leaves. Flagstar is the version where the delay is attributable to genuine investigative work rather than to a decision, and we have recorded that distinction without concluding it changes the exposure.

The Precision Is Selective

The affected count is given to the individual: 1,547,169. The description of what happened is a two-day window and nothing else — no entry route, no actor, no account of what was reached.

We have recorded at 26-0802 that a quarter of its files establish no route, and this is a characteristic instance: the number that regulators require is exact, and everything a defender elsewhere could learn from is absent. Notification regimes produce counts, not explanations.

"No Evidence Of Misuse" Is Not A Finding

The statement is almost universal in the notifications this desk reads, and it is close to unfalsifiable. Misuse of a social security number typically surfaces years later, in a credit file, attributed to nothing.

We have recorded the same phrase doing the same work at 24-0821 and 23-1110, where a company answered the alarming question rather than the informative one. Two years of monitoring against an identifier that does not expire is the arithmetic the desk files at 25-1031 and 26-0721b.

How we reported this

Compiled from contemporaneous reporting of the bank’s notification and state filings, listed below. No entry route, actor or ransom element is asserted — none was disclosed. The characterisation of this as the bank’s third disclosed breach in two years is as reported and this desk has not independently enumerated the earlier ones. Graded high on the timeline and count. Corrections: corrections@forensicpost.com.

Sources
  1. Flagstar Bank notifies 1.5 million customers of data breachBitdefender
  2. Flagstar Bank Data Breach Leaked Sensitive Information of 1.5 Million CustomersCPO Magazine
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary