TechNewsReel
Live

Flagstar Bank Settles Data Breach Class Action for $31.5 Million

Roughly 2.18 million customers are eligible for payments following two 2021 cyberattacks.

TechNewsReel Newsroom · August 5, 2026

Flagstar Bank has agreed to a $31.5 million settlement to resolve a class-action lawsuit over its failure to protect customer data. The agreement follows two separate cyberattacks in 2021 that exposed the sensitive information of millions of users.

The settlement, stemming from the case Angus et al. v. Flagstar Bank, N.A. filed in the U.S. District Court for the Eastern District of Michigan, covers approximately 2,187,170 people, including roughly 364,000 residents of California. Under the terms of the deal, eligible class members who provide documentation for financial losses directly related to the breaches may receive up to $25,000. For those who do not seek reimbursement for documented losses, the estimated cash payment is approximately $60, though the final amount could reach as high as $599.

The Path to Settlement

The legal action originated from two distinct security failures that occurred in January and December 2021. Plaintiffs alleged that Flagstar Bank, one of the largest regional banks in the United States, failed to implement adequate security measures to safeguard personal data. Furthermore, the lawsuit claimed the bank was slow to notify affected customers after the cyberattacks were discovered, leaving users vulnerable to potential identity theft and fraud for an extended period.

While Flagstar Bank has denied any wrongdoing, the institution agreed to the payout to avoid the prospect of prolonged litigation. The settlement provides a structured mechanism for consumers to recover actual financial losses and obtain identity protection services, addressing the fallout from the 2021 incidents.

Industry Implications

This case underscores the escalating legal and financial risks facing the banking sector regarding data privacy and the timeliness of breach notifications. The inclusion of specific statutory considerations for California residents highlights the growing influence of state-specific privacy laws, such as the California Consumer Privacy Act (CCPA), on how national settlements are structured. As regulators and courts increase scrutiny on the window between a breach discovery and customer notification, banks are under more pressure to modernize their security infrastructure and transparency protocols.

Next Steps for Claimants

Eligible customers must act quickly to secure their portion of the settlement. The deadline to submit a claim is August 11, 2026. Impacted individuals are encouraged to visit the official settlement website to determine their eligibility and file the necessary documentation for either the flat-rate cash payment or the higher reimbursement for documented losses. The court's final approval process will determine the exact distribution of the $31.5 million fund based on the total number of valid claims received.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.