Xfinity notifies customers of data breach

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

Associated Press

Dec 20, 2023, 12:35 PM

Updated 219 days ago

Share:

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.
In a Monday notice to customers, Xfinity said there was unauthorized access to internal systems as a result of this vulnerability — which was previously announced by software provider Citrix — between Oct. 16 and 19.
Xfinity discovered the “suspicious activity” on Oct. 25, and in the following months determined that information was “likely acquired.” On Dec. 6, the company concluded that information included usernames and hashed passwords — and, for some customers, the last four digits of Social Security numbers, account security questions, birthdates and contact information.
Analysis of the breach is still continuing but to date, Xfinity is “not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” the company said in a statement sent to The Associated Press Tuesday.
Xfinity is also requiring customers to reset their passwords, while strongly recommending two-factor or multifactor authentication.
A filing with Maine's office of the attorney general disclosed that nearly 35.9 million people were affected by this breach. The company declined to confirm a specific number Tuesday, but noted the filing's figure represents user IDs.
Philadelphia-based Comcast has more than 32 million broadband customers, according a recent earnings release.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed “Citrix Bleed,” has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new rules that went into effect Monday, the Securities Exchange Commission now requires public companies to disclose all cybersecurity breaches that could affect their bottom lines — within four days of determining a breach is material. As of Tuesday, there were no SEC filings from Comcast about the recent data breach and the company did not immediately address it.


More from News 12
0:32
Police arrest man in connection to shooting murders in Clinton Hill

Police arrest man in connection to shooting murders in Clinton Hill

1:40
Nearly 300 probationary firefighters join the ranks of FDNY

Nearly 300 probationary firefighters join the ranks of FDNY

1:46
Sunny and warm weather with lower humidity for the weekend in Brooklyn

Sunny and warm weather with lower humidity for the weekend in Brooklyn

1:08
East Flatbush residents 'Occupy the Corner' for a safe summer

East Flatbush residents 'Occupy the Corner' for a safe summer

1:24
G train shutdown impacting Bed-Stuy commuters negatively

G train shutdown impacting Bed-Stuy commuters negatively

1:44
Gun detectors could arrive in NYC subway stations today as NYPD prepares pilot program

Gun detectors could arrive in NYC subway stations today as NYPD prepares pilot program

1:43
Welder Underground unveils ‘Rappin' Max Robot’ through apprenticeship program

Welder Underground unveils ‘Rappin' Max Robot’ through apprenticeship program

0:47
Attorney General James releases body camera footage of fatal officer-involved shooting in East Flatbush

Attorney General James releases body camera footage of fatal officer-involved shooting in East Flatbush

0:24
Police: Suspect wanted for punching 72-year-old man at 25th Street subway station

Police: Suspect wanted for punching 72-year-old man at 25th Street subway station

2:10
Boar’s Head deli meat recalled for potential listeria contamination

Boar’s Head deli meat recalled for potential listeria contamination

1:44
The Real Deal: How to save on expenses amid rising costs in New York

The Real Deal: How to save on expenses amid rising costs in New York

1:36
Students set to receive OMNY cards with more rides and less restrictions

Students set to receive OMNY cards with more rides and less restrictions

1:31
Tenants in Flatbush building say they are living with broken floors, mold, leaks and holes

Tenants in Flatbush building say they are living with broken floors, mold, leaks and holes

1:41
Neighbors describe MTA bus crashing into Burger King in Kensington

Neighbors describe MTA bus crashing into Burger King in Kensington

1:46
YMCA promotes swim safety services on World Drowning Prevention Day

YMCA promotes swim safety services on World Drowning Prevention Day

0:37
Brooklyn DA: Former teacher accused of enticing teenagers to send him explicit images

Brooklyn DA: Former teacher accused of enticing teenagers to send him explicit images

1:14
New lawsuits filed against Gov. Hochul's congestion pricing plan pause

New lawsuits filed against Gov. Hochul's congestion pricing plan pause

1:35
Rally outside Brooklyn Public Library calls for end to alleged 'power grab' from Mayor Adams

Rally outside Brooklyn Public Library calls for end to alleged 'power grab' from Mayor Adams

1:55
Residents say rats are taking over Sheepshead Bay street

Residents say rats are taking over Sheepshead Bay street

0:29
Southwest breaks 50-year tradition and will assign seats; profit falls at Southwest, American

Southwest breaks 50-year tradition and will assign seats; profit falls at Southwest, American