Flagstar Bank has agreed to a $31.5 million [3] class-action settlement for customers affected by data breaches in 2021.
This settlement provides a legal pathway for victims to recover financial losses resulting from the bank's failure to protect sensitive customer information. Because the deadline for filing claims is approaching, eligible individuals must act quickly to secure compensation.
The settlement stems from two separate cyberattacks that occurred in 2021. These breaches affected nearly 2.2 million [2] people, though some reports estimate the number at approximately 2.1 million [1]. The lawsuit alleged that the regional bank failed to implement sufficient security measures to prevent the unauthorized access of data.
Eligible claimants can receive payments varying based on their documented losses. Payouts range from about $60 [5] up to a maximum of $25,000 [4]. The higher tier of compensation is reserved for those who can provide documentation of significant financial harm caused by the breach.
To receive a payment, affected customers must submit their claims by Aug. 11, 2026 [6]. This deadline is a strict cutoff for all eligible Americans seeking to participate in the fund.
Flagstar Bank operates as a regional institution in the U.S., and the settlement is being administered through a U.S. court. The fund is designed to resolve the legal disputes arising from the security lapses that exposed millions of users to potential identity theft, and fraud.
“Payouts range from about $60 up to a maximum of $25,000.”
This settlement highlights the ongoing legal and financial liabilities regional banks face following cybersecurity failures. By establishing a tiered payout system, ranging from small flat fees to substantial documented loss reimbursements, the court is addressing both general privacy violations and specific financial damages. The relatively short window for claims suggests a move toward finality in the litigation process for the 2021 breaches.


