Xfinity notifies customers of data breach

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

Associated Press

Dec 20, 2023, 12:35 PM

Updated 219 days ago

Share:

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.
In a Monday notice to customers, Xfinity said there was unauthorized access to internal systems as a result of this vulnerability — which was previously announced by software provider Citrix — between Oct. 16 and 19.
Xfinity discovered the “suspicious activity” on Oct. 25, and in the following months determined that information was “likely acquired.” On Dec. 6, the company concluded that information included usernames and hashed passwords — and, for some customers, the last four digits of Social Security numbers, account security questions, birthdates and contact information.
Analysis of the breach is still continuing but to date, Xfinity is “not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” the company said in a statement sent to The Associated Press Tuesday.
Xfinity is also requiring customers to reset their passwords, while strongly recommending two-factor or multifactor authentication.
A filing with Maine's office of the attorney general disclosed that nearly 35.9 million people were affected by this breach. The company declined to confirm a specific number Tuesday, but noted the filing's figure represents user IDs.
Philadelphia-based Comcast has more than 32 million broadband customers, according a recent earnings release.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed “Citrix Bleed,” has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new rules that went into effect Monday, the Securities Exchange Commission now requires public companies to disclose all cybersecurity breaches that could affect their bottom lines — within four days of determining a breach is material. As of Tuesday, there were no SEC filings from Comcast about the recent data breach and the company did not immediately address it.


More from News 12
2:10
Boar’s Head deli meat recalled for potential listeria contamination

Boar’s Head deli meat recalled for potential listeria contamination

2:16
Fire at Fair Lawn strip mall destroys multiple businesses, including popular Zadies Bakery

Fire at Fair Lawn strip mall destroys multiple businesses, including popular Zadies Bakery

3:00
Beautiful weekend ahead for New Jersey with sunny skies and warm temperatures

Beautiful weekend ahead for New Jersey with sunny skies and warm temperatures

1:43
Lead found on Keyport beach not ‘urgent risk’ to public health, no need to close beach

Lead found on Keyport beach not ‘urgent risk’ to public health, no need to close beach

0:55
EPA completes Phase 1 of superfund site cleanup at Unimatic Manufacturing site in Fairfield

EPA completes Phase 1 of superfund site cleanup at Unimatic Manufacturing site in Fairfield

0:20
West New York school named for Sen. Menendez to revert to original name

West New York school named for Sen. Menendez to revert to original name

0:30
Attorney general: NJ state trooper ‘inexcusably crossed the line,’ admits to punching handcuffed woman in the face in 2022

Attorney general: NJ state trooper ‘inexcusably crossed the line,’ admits to punching handcuffed woman in the face in 2022

0:15
East Brunswick police: Bicyclist killed in Route 18 crash

East Brunswick police: Bicyclist killed in Route 18 crash

0:30
No one injured in Kenilworth house fire

No one injured in Kenilworth house fire

1:04
Attorney general releases body camera footage of fatal Hamilton police-involved shooting

Attorney general releases body camera footage of fatal Hamilton police-involved shooting

0:15
Part of Manchester’s Harry Wright Lake closed due to high levels of fecal bacteria

Part of Manchester’s Harry Wright Lake closed due to high levels of fecal bacteria

0:23
2 dead in Maine plane crash after leaving New Jersey airport

2 dead in Maine plane crash after leaving New Jersey airport

0:18
$1 million lottery ticket won from $20 scratch-off at North Wildwood Wawa

$1 million lottery ticket won from $20 scratch-off at North Wildwood Wawa

1:59
Paws & Pals: Felicity now up for adoption at Associated Humane Societies

Paws & Pals: Felicity now up for adoption at Associated Humane Societies

1:17
Gov. Murphy discusses potential Menendez replacement on ‘Ask Gov. Murphy’

Gov. Murphy discusses potential Menendez replacement on ‘Ask Gov. Murphy’

0:40
State, federal lawmakers introduce legislation to shorten funding gap for World Trade Center Health Program

State, federal lawmakers introduce legislation to shorten funding gap for World Trade Center Health Program

0:33
New Jersey now has 21 towns where starter homes cost more than $1 million

New Jersey now has 21 towns where starter homes cost more than $1 million

0:48
Jersey Proud: Dean Martin & Jerry Lewis first performed together 78 years ago in Atlantic City

Jersey Proud: Dean Martin & Jerry Lewis first performed together 78 years ago in Atlantic City

1:47
Police: 3 people hospitalized as bee swarm takes over Paramus neighborhood

Police: 3 people hospitalized as bee swarm takes over Paramus neighborhood

0:23
Prosecutor: 15-year-old charged with murder in deadly Trenton shooting

Prosecutor: 15-year-old charged with murder in deadly Trenton shooting