Flagstar Bank disclosed a breach affecting 1,547,169 customers, reporting the intrusion as having occurred on 3 and 4 December 2021. The investigation concluded on 2 June 2022, and customers were notified from 17 June. Names, other personal information and social security numbers were accessed. Two years of identity monitoring were offered.
Reporting at the time noted this as the third breach disclosed by the bank in two years. The company stated it had no evidence that personal information had been misused.
Six Months, Of Which The Investigation Was Most
The interval from intrusion to notification is roughly six and a half months, and it decomposes usefully: about six months to conclude an investigation, then a fortnight to write to people.
We filed this interval constantly — 289 days at 26-0721b, four months at 22-0404, ten months from detection to disclosure at 23-0808b — and argues the clock that matters to an affected person starts when the data leaves. Flagstar is the version where the delay is attributable to genuine investigative work rather than to a decision, and we have recorded that distinction without concluding it changes the exposure.
The Precision Is Selective
The affected count is given to the individual: 1,547,169. The description of what happened is a two-day window and nothing else — no entry route, no actor, no account of what was reached.
We have recorded at 26-0802 that a quarter of its files establish no route, and this is a characteristic instance: the number that regulators require is exact, and everything a defender elsewhere could learn from is absent. Notification regimes produce counts, not explanations.
"No Evidence Of Misuse" Is Not A Finding
The statement is almost universal in the notifications this desk reads, and it is close to unfalsifiable. Misuse of a social security number typically surfaces years later, in a credit file, attributed to nothing.
We have recorded the same phrase doing the same work at 24-0821 and 23-1110, where a company answered the alarming question rather than the informative one. Two years of monitoring against an identifier that does not expire is the arithmetic the desk files at 25-1031 and 26-0721b.
Compiled from contemporaneous reporting of the bank’s notification and state filings, listed below. No entry route, actor or ransom element is asserted — none was disclosed. The characterisation of this as the bank’s third disclosed breach in two years is as reported and this desk has not independently enumerated the earlier ones. Graded high on the timeline and count. Corrections: corrections@forensicpost.com.