Flagstar Bank Data Breach Settlement $31.5 Million for 2.19 Million Customers

The Flagstar Bank Data Breach Settlement $31.5 Million for 2.19 Million Customers settlement offers $31.50M in total to eligible claimants who be a customer of flagstar bank (flagstar bank, n.a.) whose personal information was potentially affected by the data breach described in the settlement notice. The filing deadline has not yet been announced. Proof of purchase is not required.
Deadline: No deadline specified
Total amount allocated for all claims
Estimated amount per eligible claim
No proof of purchase needed — anyone eligible can file a claim
Proof required depends on the claim type. Generally, you must submit the settlement claim form with identifying information, and if you are requesting reimbursement for losses (such as certain out-of-pocket expenses), you must provide supporting documentation (e.g., receipts, invoices, credit monitoring invoices, or other records) showing the amount and that the expense relates to the breach. Claimants may also need to follow instructions for confirming eligibility (such as using the notice information or class list details).
Settlement Summary
Flagstar Bank faced a major cybersecurity incident that exposed sensitive information belonging to about 2.19 million customers, prompting a class action lawsuit (Angus et al. v. Flagstar Bank, N.A., Case No. 2:21-cv-10657-MFL-DRG). Data breaches like this often involve hackers gaining unauthorized access to systems that store personal data—such as names, contact details, and potentially account-related information—and can trigger serious downstream risks like identity theft and fraud. In response to allegations that the bank failed to adequately protect customer information, the case moved through federal court in Michigan, where a settlement has now been proposed as a way to compensate affected people. The lawsuit was filed because customers alleged the breach caused harm and that the bank’s security practices were insufficient under prevailing expectations for protecting consumer data. The settlement creates a $31.5 million fund for eligible class members, with notice and claims handled through the settlement website, FlagstarSettlement.com. Its significance goes beyond one bank: settlements in data-breach cases help establish accountability and create practical redress for large-scale exposure events, especially when millions of records are involved. They also send a message that courts may scrutinize how financial institutions manage cybersecurity risks—an area shaped by regulations such as the Gramm-Leach-Bliley Act’s Safeguards Rule, plus industry guidance from the Federal Trade Commission and, for many banks, oversight frameworks tied to protecting consumer financial information. Broader implications include the likelihood of heightened compliance and improved security controls across the banking industry, from stronger authentication and monitoring to clearer incident-response plans and vendor risk management. Similar cases often follow a pattern: plaintiffs argue negligence or failure to implement reasonable security measures; banks typically deny wrongdoing but may agree to settlements to avoid prolonged litigation and uncertainty. As cybersecurity threats continue to evolve, this settlement reflects a wider trend in consumer protection—where regulators and courts increasingly focus on whether organizations took appropriate steps to safeguard personal and financial data before an intrusion occurs, reinforcing the idea that security failures can become both legal and regulatory issues for institutions serving the public.
Entities Involved
Related Topics
Eligibility Requirements
- Be a customer of Flagstar Bank (Flagstar Bank, N.A.) whose personal information was potentially affected by the data breach described in the settlement notice
- Be identified as eligible/impacted in the class list or by documentation provided with the claim instructions (e.g., notice letter or online eligibility check)
- Submit a claim form by the applicable deadline specified in the official settlement notice
- Provide required identifying information consistent with the settlement’s claim process
- If reimbursement or additional damages are claimed, include the requested documentation for out-of-pocket losses (as applicable)
Featured Investigations
Important Notice About Filing Claims
Submitting false information in a settlement claim is considered perjury and will result in your claim being rejected. Fraudulent claims harm legitimate class members and may result in legal consequences.
If you are unsure about your eligibility for this settlement, please visit the official settlement administrator’s website using the link provided above. Review the eligibility criteria carefully before submitting a claim.
Class Action Champion is an independent information resource and is not affiliated with any settlement administrator, law firm, or court. We provide settlement information as a service to help connect eligible class members with legitimate settlements.
