TechNewsReel
Live

Flagstar Bank to Pay $31.5 Million to Settle 2021 Data Breach Lawsuits

The settlement resolves class-action litigation after two separate security incidents exposed the data of over 2 million U.S. consumers.

TechNewsReel Newsroom · August 4, 2026

Flagstar Bank has agreed to a $31.5 million settlement to resolve class-action lawsuits following two separate data breaches in 2021. The agreement concludes the legal action known as Angus, et al. v. Flagstar Bank, N.A., which was filed after millions of customers had their personal information compromised.

Approximately 2,187,170 U.S. consumers were identified as impacted by the security failures. The first breach occurred in January 2021 and involved a third-party file-sharing platform, Accellion, which allowed cybercriminals to access sensitive data. A second, separate breach occurred in December 2021. The compromised information included highly sensitive personally identifiable information (PII), such as Social Security numbers, birthdates, names, and banking details.

Settlement Terms and Consumer Benefits

Eligible class members can apply for several tiers of compensation. Those who can prove documented financial losses resulting from the breaches may claim up to $25,000. Additionally, eligible members may receive a cash payment, currently estimated at approximately $60, and three years of credit monitoring services to protect against identity theft. Residents of California may be eligible for further compensation of up to $100 under the California Consumer Privacy Act (CCPA).

Consumers who believe they were affected have a significant window to act, as the deadline to submit a claim for benefits is August 11, 2026. The settlement is designed to provide a structured mechanism for the millions of affected individuals to recover losses and secure their credit identities after the exposure of their private data.

Industry Implications and Third-Party Risk

This case underscores the systemic vulnerability of financial institutions to third-party software flaws. The involvement of the Accellion platform in the first breach highlights a recurring trend where banks are compromised not through their own primary systems, but through the vendors they employ for file sharing and data management. For the banking industry, this settlement serves as a reminder that legal and financial liability remains with the primary institution even when the technical failure occurs at a vendor level.

As financial institutions continue to digitize and outsource core functions, the risk of PII leaks remains a critical operational threat. The scale of this settlement reflects the increasing cost of data negligence and the growing appetite for class-action litigation when consumer privacy is breached on a mass scale.

Next Steps for Affected Users

Impacted consumers should verify their eligibility through the official settlement channels and gather documentation for any financial losses incurred since 2021. While the settlement provides a path to recovery, the long-term impact of the leaked Social Security numbers and banking details means that affected users should remain vigilant regarding their credit reports and account activity for years to come.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.