If you notice that major data breaches don’t happen all at once but in slow, methodical waves, it can be a little unsettling. The attack came first. After that, there was silence. Then, after years, you get a letter or a push notification telling you that someone stole your personal information and has agreed to pay for it. This is about where millions of Flagstar Bank customers are at the moment.
There were two separate cyberattacks on Flagstar in 2021. Flagstar is a New York-based regional bank that offers services like checking accounts, mortgages, and wealth management. The first was in January and put the information of just over 1.4 million customers at risk. The second one came in December of that same year and killed more than 1.5 million people. The two events together affected more than two million people, including about 364,000 people who live in California.
Lawsuits that followed said Flagstar hadn’t done enough to keep private customer data safe and hadn’t told those who were affected quickly enough. This is what banks usually do: they say they did nothing wrong. But after a mediation process led by a retired federal judge, Flagstar agreed to settle. They set up a $31.5 million fund to settle the claims quickly and without the uncertainty of a full trial.
Take a moment to think about that number. $31.5 million seems like a lot of money. If you divide that amount by the 2.1 million people who are eligible to make a claim, you get about $14.40 per person before legal fees, administrative costs, and other costs are taken out. The numbers don’t show as much as the headline number makes it seem.

Still, each claimant’s payout can be very different depending on what they went through and what they can prove. People who have proof of financial harm, like fraudulent charges, identity theft costs, or credit monitoring costs, can get up to $25,000 back. That ceiling is not given out for free. It needs paper work, like bank statements, receipts, credit reports, invoices, or anything else that shows a link between the loss and the breach. The process is meant to be hard, which is probably for the best since large class-action pools can be abused.
A “residual cash payment” is what the settlement calls the most likely outcome for most claimants. That number is thought to be around $60 per person right now, but the exact amount will depend on how many valid claims come in and how much money is left in the fund after higher-priority payments are made. The remaining payment can’t be more than $599. California residents get a small extra benefit: up to $100 in statutory payments. However, this amount could be lowered if demand is higher than the amount of money set aside for it.
People must have been told by Flagstar that their information was compromised in order to be eligible at all. Notices were sent by email and regular mail, and each one had a unique claim identification number on it. The settlement administrator can be reached by phone by anyone who thinks they should be included but can’t find the notice. The last day to file is August 11, 2026, which is not too far away now.
There is a bigger anger that’s building up behind settlements like this one. Customers didn’t choose for their information to be made public. They didn’t agree to go through the legal process that came next. And a lot of people will get a check that’s barely enough for a restaurant dinner if they file at all. For some, the act of claiming might have more of a symbolic value than a financial one. For some, especially those who actually had identity theft or fraud happen after the incident, the higher level of reimbursement may really help.
The long-term effect on trust is harder to measure. Since then, Flagstar has been through its own rough patch in the banking industry. This settlement ends one chapter. But people tend to remember how a bank handled (or didn’t handle) a breach in ways that no settlement fund can fully fix.

