Flagstar Bank is warning that over 800,000 American customers are affected by a data breach after cybercriminals breached a third-party service provider.

Flagstar, now owned by New York Community Bank, is a Michigan-based financial services . Before its acquisition last year, it was one of the largest banks in the United States, with total assets of more than $31 billion.
Flagstar sent a notification to customers about the data breach. In the notification, it explains that it was indirectly affected by Fiserv, a vendor it uses for payment processing and mobile banking.
See also: Hacking groups now deploy ransomware within 24 hours of breaching victims
Fiserv appears to have been one of thousands of companies compromised by the Clop ransomware gang via a vulnerability in its MOVEit Transfer software . According to a report by Emsisoft , these attacks affected more than 64 million people and two thousand organizations worldwide.
The attackers exploited a vulnerability in the MOVEit Transfer to gain access to Fiserv's systems and, from there, were able to steal Flagstar customer data, which Fiserv held to provide services.
The types of data that was leaked are listed in the data breach notification, but the Maine Data Breach Portal lists at least names and Social Security numbers.
The total number of Flagstar Bank customers affected by this incident is 837,390 in the United States.

Third violation in two years
This latest breach is the third for Flagstar since March 2021. At the time, the bank had revealed that it had been breached by the Clop. The hackers had compromised the Accellion file transfer serverin January of that year.
See also: Sony: Data breach affects thousands of employees
Based on data samples released by the ransomware, hackers were able to steal customer and employee information, including names, addresses, phones, tax documents, and social security numbers.
In June 2022, Flagstar disclosed another breach of its corporate network that affected over 1.5 million of its customers in the United States.
Regarding the current breach, the most concerning thing is that Fiserv provides services to hundreds of banks, which it has compromised again due to other security deficiencies.
Data breaches
Data breaches are on the rise. The third breach at Flagstar Bank affected over 800,000 customers and is a stark reminder of the threat organizations and customers .
These breaches are not just digital mistakes or incidents with minimal consequences. They are, above all, attacks that destroy the core of trust between a business and its customers. They refute the claim that the protection of personal data is self-evident.
The reality of data breaches is a constant threat with far-reaching and lasting consequences, especially when such big names in the space as Flagstar Bank are involved.
See also: Motel One: Data breach following ransomware attack

The Impact of the Rise in Data Breaches
The alarming rise in data breaches has serious implications. Beyond the discomfort and insecurity felt by customers, the sums of money involved are enormous. We have already seen companies suffer huge losses, from losing customers to having their shares devalued.
It is no longer disputed that data protection is a serious issue for businesses, which must now recognize that security should not just be desirable, but essential.
Source: www.bleepingcomputer.com
