News: 1655844836

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Info on 1.5m people stolen from US bank in cyberattack

(2022/06/21)


A US bank has said at least the names and social security numbers of more than 1.5 million of its customers were stolen from its computers in December.

In a [1]statement to the office of Maine's Attorney General this month, Flagstar Bank said it was compromised between December and April 2021. The organization's sysadmins, however, said they didn't discover the intrusion until now. On June 2, they realized criminals "accessed and/or acquired" files containing personal information on 1,547,169 people.

"Flagstar experienced a cyber incident that involved unauthorized access to our network," the bank said in a statement emailed to The Register .

[2]

"Upon learning of the incident, we promptly activated our incident response plan, engaged external cybersecurity professionals experienced in handling these types of incidents, and reported the matter to federal law enforcement," it continued. "We continue to operate all services normally."

[3]

[4]

The bank has offered affected customers identity theft protection services, and late last week mailed letters

[5]PDF

notifying everyone who may have had their data stolen. "We have no evidence that any of the information has been misused," the letter stated.

Headquartered in Michigan, the bank and mortgage lender has more than 150 branches nationwide and home loan offices in 28 states.

[6]

Flagstar also suffered a security breach when, in late 2020, the Clop gang exploited a zero-day vulnerability in Accellion's legacy file-transfer appliance and siphoned data belonging to more than 100 organizations including [7]Royal Dutch Shell , defense contractor [8]Bombardier , and Flagstar. That attack exposed about 1.48 million customers' bank account information, Social Security numbers, passport data, and other private information.

[9]After oil giant Shell hit by Clop ransomware gang, workers' visas dumped online as part of extortion attempt

[10]Clop ransomware gang leaks online what looks like stolen Bombardier blueprints of GlobalEye radar snoop jet

[11]Feds raid dark web market selling data on 24 million Americans

[12]Millions of people's info stolen from MGM Resorts dumped on Telegram for free

Those customers sued the bank after that intrusion, and in September 2021, Flagstar agreed to pay $5.9 million to settle the lawsuit. Folks whose data was exposed were entitled to either three years of free credit monitoring services, or a payout between $99 and $316.

The bank also agreed to make "various enhancements" to its third-party vendor risk management program along with "other data privacy enhancements," according to court documents.

Plus, Flagstar agreed to monitor the dark web for any indications of people's personal data being sold, or other fraudulent activity related to the security breach.

In a statement provided to The Register following the latest breach disclosure, a spokesperson for the bank said: "We take the security of our network and the personal information entrusted to us with the utmost seriousness."

[13]

But after two significant data security breaches in less than two years, perhaps it's time for a fresh security strategy. ®

Get our [14]Tech Resources



[1] https://apps.web.maine.gov/online/aeviewer/ME/40/667f2112-b49f-445d-be03-dee38e32bf8e.shtml

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrI-g4Bh5RWTa9GPEVQZbAAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrI-g4Bh5RWTa9GPEVQZbAAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrI-g4Bh5RWTa9GPEVQZbAAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://regmedia.co.uk/2022/06/21/flagstar_data_breach_notification_letter.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrI-g4Bh5RWTa9GPEVQZbAAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/03/29/shell_clop_ransomware_leaks_update/

[8] https://www.theregister.com/2021/02/23/bombardier_clop_ransomware_leaks/

[9] https://www.theregister.com/2021/03/29/shell_clop_ransomware_leaks_update/

[10] https://www.theregister.com/2021/02/23/bombardier_clop_ransomware_leaks/

[11] https://www.theregister.com/2022/06/08/us_feds_raid_dark_web/

[12] https://www.theregister.com/2022/05/25/mgm_customers_data_dumped_again/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrI-g4Bh5RWTa9GPEVQZbAAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



VoiceOfTruth

-> The bank has offered affected customers identity theft protection services

We keep hearing about this. Is it actually any good? I would like to hear from somebody with experience of it, or rather a Reg write up.

-> We take the security of our network and the personal information entrusted to us with the utmost seriousness

We keep hearing this canned response too. Maybe their staff are just not up to it.

Nothing increases your golf score like witnesses.