Original Release Date: 3/11/2021
Flagstar, the US bank and mortgage lender with locations in New Jersey, disclosed a data breach in which threat actors behind the Clop ransomware group exploited a vulnerability in Accellion FTA servers in January 2021. They gained access to sensitive customer and employee information, such as Social Security numbers, names, addresses, phone numbers, and tax records. The threat actors issued a ransom note demanding bitcoin and later released screenshots of the stolen data. Since the breach, Flagstar discontinued use of the file sharing platform and informed affected customers.