Flagstar Was Breached Twice in 11 Months. Now 2.19 Million People Can Claim Up to $25,000 From a $31.5M Fund — Until Tuesday
Angus v. Flagstar covers both 2021 intrusions — the January file-transfer hack and the December network breach. The official FAQ pegs the no-receipts cash payment at an estimated $60 (capped at $599), documented losses at up to $25,000, and adds three years of three-bureau credit monitoring. Claims close August 11; the money itself waits on an October 1 hearing.
By Settlement Insight Data Desk ·
Two breaches, one fund, one deadline
Angus, et al. v. Flagstar Bank, N.A., No. 2:21-cv-10657 (E.D. Mich.) settles claims from two separate intrusions in the same year. Per the official FAQ, in January 2021 criminals “infiltrated a file sharing platform used by Flagstar” and accessed personal information of about 1.47 million people — press coverage tied that incident to the Accellion FTA file-transfer exploit that hit dozens of companies that winter. Then in December 2021, criminals “infiltrated Flagstar's network” itself, reaching data of about 1.58 million people — the intrusion Flagstar publicly disclosed in June 2022.
The combined settlement class is approximately 2,187,170 U.S. residents, including about 364,000 Californians, and the fund is $31.5 million. The claim deadline is August 11, 2026 — file online at FlagstarSettlement.com or by mail to the administrator (P.O. Box 4427, Baton Rouge, LA 70821; 1-855-542-0397).
What you can claim — with receipts and without
The documented-loss tier pays up to $25,000 per person for “unreimbursed losses relating to fraud or identity theft,” including attorney fees, credit-monitoring and credit-freeze costs, and even postage and mileage tied to dealing with the breach. No receipts? The FAQ describes a residual pro-rata cash payment estimated at $60 and capped at $599 per person. California residents can additionally claim a statutory payment of up to $100.
Separate from the cash, every class member can claim three years of credit monitoring — three-bureau monitoring with $1 million in identity-theft insurance and dark-web scanning — and it stacks with either cash tier. If you do nothing by Tuesday, you get none of it and release your claims anyway (the opt-out window closed June 29).
The honest math behind the $25,000 headline
Late-July and early-August personal-finance coverage headlined this settlement at “up to $25,000,” which is technically true and practically rare: that ceiling requires documented, unreimbursed, fraud-traceable losses. The realistic anchor for most of the 2.19 million class members is the FAQ's own $60 estimate — and even that flexes, because the cash pool is what remains after documented-loss payments, administration costs, and court-approved fees, divided pro rata among everyone who filed the simple claim.
That still clears the bar we apply to every deadline story: a no-proof claim takes minutes, $60 is a meaningful floor for it, and the $25,000 tier exists precisely for the minority who spent 2021–2022 untangling actual fraud. Check old statements before Tuesday if that might be you.
After Tuesday: October 1, appeals — and the Flagstar breach that isn't covered
Filing does not mean a check this fall by default. The final approval hearing is set for October 1, 2026, at 9:30 a.m. ET, via Zoom, and distribution follows approval plus the appeals window — the stage where other settlements have stalled for months or longer. Realistic money timeline: late 2026 at the earliest, unappealed.
One more disambiguation, because Flagstar has been in breach headlines three times: the press-reported 2023 MOVEit file-transfer incident that exposed Flagstar-linked customer data through a vendor is not part of this settlement. This fund covers the two 2021 intrusions only. If your notice letter dates from 2023–2024, don't wait on this deadline to cover you — check which incident it names. Our data breach settlement calculator covers what typical claims pay across cases.
The Data Behind This Story
- Settlement fund
- $31,500,000
- Case
- Angus v. Flagstar Bank, N.A., 2:21-cv-10657 (E.D. Mich.)
- Class size
- ≈ 2,187,170 (incl. ≈364,000 CA residents)
- Documented losses
- Up to $25,000
- No-proof cash
- Estimated $60, capped at $599 (pro rata)
- California statutory payment
- Up to $100
- Credit monitoring
- 3 years, three-bureau + $1M insurance
- Claim deadline
- August 11, 2026
- Final approval hearing
- October 1, 2026 (Zoom)
- Source: flagstarsettlement.com and /faqs — official administrator site: fund, class size, both breach descriptions (“file sharing platform” Jan 2021 ≈1.47M; “Flagstar's network” Dec 2021 ≈1.58M), benefit tiers and caps, deadlines, hearing date and format, contact details (fetched and verified August 8, 2026)
- Source: Angus, et al. v. Flagstar Bank, N.A., No. 2:21-cv-10657-MFL-DRG (E.D. Mich.) — case caption per settlement notice and court documents
- Source: Press context (attributed): January 2021 incident linked to the Accellion FTA exploit; December 2021 network intrusion disclosed June 2022; separate 2023 MOVEit vendor incident — not covered by this settlement
- Source: CNBC Select and Yahoo Finance, early August 2026: the “up to $25,000” coverage wave driving current searches
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.