Xfinity notifies customers of data breach

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

Associated Press

Dec 20, 2023, 12:35 PM

Updated 219 days ago

Share:

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.
In a Monday notice to customers, Xfinity said there was unauthorized access to internal systems as a result of this vulnerability — which was previously announced by software provider Citrix — between Oct. 16 and 19.
Xfinity discovered the “suspicious activity” on Oct. 25, and in the following months determined that information was “likely acquired.” On Dec. 6, the company concluded that information included usernames and hashed passwords — and, for some customers, the last four digits of Social Security numbers, account security questions, birthdates and contact information.
Analysis of the breach is still continuing but to date, Xfinity is “not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” the company said in a statement sent to The Associated Press Tuesday.
Xfinity is also requiring customers to reset their passwords, while strongly recommending two-factor or multifactor authentication.
A filing with Maine's office of the attorney general disclosed that nearly 35.9 million people were affected by this breach. The company declined to confirm a specific number Tuesday, but noted the filing's figure represents user IDs.
Philadelphia-based Comcast has more than 32 million broadband customers, according a recent earnings release.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed “Citrix Bleed,” has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new rules that went into effect Monday, the Securities Exchange Commission now requires public companies to disclose all cybersecurity breaches that could affect their bottom lines — within four days of determining a breach is material. As of Tuesday, there were no SEC filings from Comcast about the recent data breach and the company did not immediately address it.


More from News 12
1:49
Bridgeport church reported finding hundreds of hypodermic needles on parish property this week

Bridgeport church reported finding hundreds of hypodermic needles on parish property this week

1:34
Sunny this weekend, chance of storms next week

Sunny this weekend, chance of storms next week

2:13
‘You know who I am?’ Police video shows Bridgeport councilman’s ‘combative’ traffic stop

‘You know who I am?’ Police video shows Bridgeport councilman’s ‘combative’ traffic stop

0:26
Boat Camp introduces kids to the beauty of Long Island Sound

Boat Camp introduces kids to the beauty of Long Island Sound

0:16
Police: Norwalk man arrested for committing lewd acts against a family member in San Diego

Police: Norwalk man arrested for committing lewd acts against a family member in San Diego

2:33
Can swimming become dangerous due to extremely high water surface temperatures?

Can swimming become dangerous due to extremely high water surface temperatures?

0:42
 Real Deal: Natural gas, rent and medical care continue to increase in Connecticut

Real Deal: Natural gas, rent and medical care continue to increase in Connecticut

0:20
Little boy helps rescue dog in Stratford

Little boy helps rescue dog in Stratford

0:51
Norwalk celebrates 34th anniversary of the Americans with Disabilities Act

Norwalk celebrates 34th anniversary of the Americans with Disabilities Act

1:57
'It's powerful.' NHL stars participate in Stamford fundraiser to raise awareness of suicide prevention

'It's powerful.' NHL stars participate in Stamford fundraiser to raise awareness of suicide prevention

2:08
63rd annual summer book sale begins at Pequot Library in Southport

63rd annual summer book sale begins at Pequot Library in Southport

0:31
Shelton homeowner faces charges after illegal fireworks cause fire to escalate

Shelton homeowner faces charges after illegal fireworks cause fire to escalate

1:57
Bridgeport Police Department swears in dozens of new recruits

Bridgeport Police Department swears in dozens of new recruits

2:00
Harris campaign highlights challenges female candidates face in CT

Harris campaign highlights challenges female candidates face in CT

0:14
Officials: West Nile virus confirmed in mosquitoes collected from Danbury testing site

Officials: West Nile virus confirmed in mosquitoes collected from Danbury testing site

0:56
Free life jacket station unveiled at Lake Simmons in Greenwich

Free life jacket station unveiled at Lake Simmons in Greenwich

0:43
Connecticut resident awarded Caregiver of the Year award at BrightStar Care in Norwalk

Connecticut resident awarded Caregiver of the Year award at BrightStar Care in Norwalk

0:32
Connecticut State Police rescue ducks from Interstate-91 in Hartford

Connecticut State Police rescue ducks from Interstate-91 in Hartford

2:46
Main Street Connecticut: Showcasing the best of Weston

Main Street Connecticut: Showcasing the best of Weston

0:56
Norwalk unveils new playground at Flax Hill Park

Norwalk unveils new playground at Flax Hill Park