Flagstar Bank has agreed to a proposed $31.5 million class action settlement over two data breaches that occurred in 2021 and affected the personal information of approximately 2.19 million people in the United States. Eligible class members can seek reimbursement for documented losses of up to $25,000, a residual cash payment, three years of credit monitoring, and, for qualifying California residents, an additional statutory payment.
The claim deadline is August 11, 2026, making the settlement especially time-sensitive for people who received an official notice. The case is Angus, et al. v. Flagstar Bank, N.A., pending in the U.S. District Court for the Eastern District of Michigan.

What Is the Flagstar Bank Data Breach Settlement?
The settlement resolves allegations arising from two separate cybersecurity incidents at Flagstar. According to the court-approved notice, one incident occurred in January 2021 and involved a file-sharing platform used by the bank. A second cyberattack occurred in December 2021 and involved Flagstar’s network.
The two incidents affected the personal information of about 2,187,170 U.S. consumers, including roughly 364,000 California residents. Plaintiffs alleged that Flagstar did not adequately protect personal information and delayed notifying affected consumers. Flagstar denies the claims, and the court has not made a finding that the bank did anything wrong.
How Much Is the Flagstar Settlement?
The proposed agreement requires Flagstar to create a $31.5 million settlement fund. The fund will pay valid class-member benefits as well as approved administration costs, attorneys’ fees and expenses, and service awards.
Because several types of benefits are paid from the same fund, the exact amount of some payments will depend on the number of valid claims and the money remaining after other approved expenses are deducted.
Who Is Eligible for the Settlement?
A person is generally part of the settlement class if Flagstar identified that person’s personal information as having been affected by either or both of the 2021 data breaches. Notices were sent by email or direct mail to identified class members.
The settlement includes a nationwide class of approximately 2.19 million people and a California subclass of about 364,000 residents. People who validly opted out are not eligible for settlement benefits.
Up to $25,000 for Documented Monetary Losses
Class members may claim reimbursement of documented monetary losses fairly traceable to the breaches, up to $25,000 per person. Eligible losses can include unreimbursed fraud or identity-theft losses, professional fees, credit-repair expenses, costs of freezing or unfreezing credit, credit-monitoring costs, and certain related expenses such as postage or copying.
Supporting documentation is required for this category. The settlement administrator will review the materials and determine whether the claimed losses qualify.
Residual Cash Payment of About $60
All eligible class members may also request a residual cash payment. Class counsel currently estimates this payment at about $60, but the final amount may be higher or lower. The payment cannot exceed $599 per person.
Importantly, the residual cash payment can be claimed in addition to reimbursement for documented monetary losses. Its final value will be calculated after other settlement expenses and valid claims are paid.
Extra Payment for California Residents
Class members who lived in California at the time of the breaches may request a statutory cash payment of up to $100. This benefit may be claimed along with other available settlement benefits, subject to the terms of the agreement and any required pro rata reductions.
Three Years of Free Credit Monitoring
Eligible claimants may also choose three years of three-bureau credit monitoring and identity-theft protection services. The package includes monitoring of all three major credit bureaus, $1 million in identity-theft insurance, dark-web monitoring, identity-restoration assistance, advisory services, and lost-wallet assistance.
What Is the Flagstar Settlement Claim Deadline?
The deadline to submit a claim is August 11, 2026. Online claims must be filed by that date, while mailed claim forms must be postmarked no later than August 11. Consumers seeking documented-loss reimbursement should make sure they include the required supporting evidence.
The deadlines for objecting to or opting out of the settlement passed on June 29, 2026.
When Will Flagstar Settlement Payments Be Sent?
Payments are not expected immediately after the claim deadline. The court has scheduled a final approval hearing for October 1, 2026, at 9:30 a.m. Eastern Time. The judge will decide whether the proposed settlement should receive final approval.
If the settlement is approved, payments will be distributed after the agreement becomes effective and any appeals are resolved. The official notice warns that appeals can delay distribution, potentially for a significant period.
What Should Affected Consumers Do Now?
Anyone who received an official Flagstar settlement notice should review it promptly because the August 11 claim deadline is close. A class member who does nothing will not receive settlement benefits and, if the agreement becomes final, will generally release the claims covered by the settlement.
The proposed $31.5 million Flagstar Bank data breach settlement therefore offers several forms of relief, but eligible consumers must submit a valid claim on time to receive cash compensation or credit-monitoring benefits.