Article Details
Scrape Timestamp (UTC): 2023-10-08 14:09:57.351
Original Article Text
Click to Toggle View
Third Flagstar Bank data breach since 2021 affects 800,000 customers. Flagstar Bank is warning that over 800,000 US customers had their personal information stolen by cybercriminals due to a breach at a third-party service provider. Flagstar, now owned by the New York Community Bank, is a Michigan-based financial services provider that, before its acquisition last year, was one of the largest banks in the United States, having total assets of over $31 billion. A data breach notification sent to impacted customers explains that Flagstar was indirectly impacted by Fiserv, a vendor it uses for payment processing and mobile banking services. Fiserv was breached in the widespread CLOP MOVEit Transfer data theft attacks that have impacted over 64 million people and two thousand organizations worldwide, according to a report by Emsisooft. The attackers exploited a zero-day vulnerability in the MOVEit Transfer product to access Fiserv’s systems and, from there, stole Flagstar customer data the vendor held to provide services. The types of data that were compromised are redacted in the sample data breach notification letters. However, the entry on Maine’s data breach portal lists at least names and Social Security Numbers (SSNs) as stolen by the threat actors. The total number of Flagstar Bank customers impacted by this incident is 837,390 in the United States. A third breach in two years This latest breach is the third for Flagstar since March 2021, when it disclosed it suffered a breach from the Clop ransomware gang, who, at that time, hacked its Accellion file transfer server in January of that year. Based on the data samples posted by the ransomware gang, the hackers managed to steal customer and employee information, including names, addresses, phone numbers, tax records, and SSNs. In June 2022, Flagstar disclosed another breach of its corporate network that impacted over 1.5 million of its customers in the U.S. The data compromised in that incident includes at least names and Social Security Numbers. At the time, the company opted again to censor the relevant section on the published notification samples. What is more worrying is that Fiserv offers services to hundreds of banks, which it has indirectly exposed in the past due to other security lapses. BleepingComputer has contacted Fiserv to ask if the MOVEit breach affects more financial institutions and their customers, and we will update this post as soon as we receive a response.
Daily Brief Summary
Flagstar Bank warns that a cyber breach at third-party payment processing and mobile banking provider, Fiserv, has led to the theft of personal information of around 837,390 of its customers in the US.
Fiserv was infiltrated through the broad CLOP MOVEit Transfer data theft attack, which exploited a zero-day vulnerability in the MOVEit Transfer product to gain access to systems and steal customer data.
Data stolen reportedly comprises customer names and social security numbers (SSNs), although official documentation has redacted the precise nature of the compromised data.
This third data breach which Flagstar Bank has suffered since March 2021 follows a previous Clop ransomware attack that affected its Accellion file transfer server and a breach of its corporate network in June 2022 which had impacted over 1.5 million customers.
Concerns have been raised about Fiserv’s overall security as the company provides services to hundreds of banks; responses from Fiserv regarding the moving breach affecting further financial institutions and customers are pending.