The fact that a bank was hacked twice in the same year is subtly unsettling. In 2021, Flagstar Bank, a significant regional organization with approximately 340 branches nationwide and roots dating back to 1859, found itself in precisely that situation. Nearly 2.2 million customers’ personal information was compromised by two different cyberattacks, one in January and another in December. In order to resolve the ensuing class-action lawsuit, the bank has agreed to pay $31.5 million years later.
Claims for the Flagstar Cyberattack 2021 Settlement Fund are now being accepted, and if your information was compromised in either breach, you might have money that you haven’t yet received.
Approximately 1.4 million customers’ data was compromised in the January 2021 attack. An additional 1.5 million were affected by the December breach. The lawsuit’s plaintiffs claimed that Flagstar not only neglected to properly safeguard private information, but it also took too long to notify impacted clients, which is a crucial detail in situations like this. The bank maintains that it did nothing improper and has denied any wrongdoing. However, it consented to a settlement, primarily to avoid the expense and uncertainty of a protracted trial.
In corporate data breach lawsuits, that is a common pattern. Companies frequently choose the settlement route because the math works out that way rather than because they think they were wrong. Admitting fault and fighting in court are two very different calculations. The courts may never formally address whether Flagstar’s security procedures were truly insufficient. It’s evident that 2.1 million people’s personal information was compromised, and they now stand to gain financially.
Although the amounts vary greatly based on what claimants can document, the settlement structure is rather simple. Reimbursement up to $25,000 is available to those who can demonstrate specific, out-of-pocket losses related to the breaches, such as fraud charges, identity theft expenses, or credit monitoring fees. That’s a significant check, but it needs documentation and evidence. Under the California Consumer Privacy Act, impacted Californians have a slightly different arrangement that allows them to receive up to $100 regardless of any documented harm.

If the pool of legitimate claims turns out to be smaller than anticipated, the remaining cash payment for everyone else is capped at $599 and is estimated to be around $60. It’s not a huge sum of money, but it’s something, especially for those who had to spend hours on hold with their bank or credit card company to deal with the fallout. Additionally, each claimant can choose to add three years of three-bureau credit monitoring thru IDX, which includes identity restoration services, dark web monitoring, and $1 million in identity theft insurance. To be honest, some people might value that package more than the money.
A final fairness hearing was set for October 11, 2026, and the claim deadline was August 11, 2026. Payments would be made via PayPal, Venmo, Zelle, or paper check if the case is accepted without additional appeals. Attorneys’ fees and lead plaintiff costs would be paid first.
It’s important to remember that the 2021 incidents weren’t the only reason Flagstar was hit with a class-action settlement. The bank was fined $3.5 million by the Securities and Exchange Commission in December 2024 for allegedly making false statements regarding the breaches. This was an additional consequence that gave the already substantial legal exposure a regulatory component. Flagstar paid the fine and consented to stop and desist, but it neither acknowledged nor denied those accusations.
Somewhere in all of this is a more general lesson. Financial institution data breaches are becoming more common, and the most damaging period is frequently the time between an attack and customers learning about it. That delay turned into a major grievance in Flagstar’s case. The message is rather straightforward for customers: it is no longer reasonable to assume that your bank’s systems are impenetrable, and keeping an eye on your own credit and accounts is essential financial hygiene.
The settlement website and administrator hotline at 1-855-542-0397 are good places to start if you think your information was impacted but haven’t filed yet. Any money you may have been owed is forfeited if you miss the window.