Toll of Commuting
News12 New York
Where to Watch
Download the App
Local
Crime
Weather
beWell
The East End
Crime Files

Xfinity notifies customers of data breach

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

Associated Press

Dec 20, 2023, 7:35 AM

Updated

Share:

More Stories

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

In a Monday notice to customers, Xfinity said there was unauthorized access to internal systems as a result of this vulnerability — which was previously announced by software provider Citrix — between Oct. 16 and 19.

Xfinity discovered the “suspicious activity” on Oct. 25, and in the following months determined that information was “likely acquired.” On Dec. 6, the company concluded that information included usernames and hashed passwords — and, for some customers, the last four digits of Social Security numbers, account security questions, birthdates and contact information.

Analysis of the breach is still continuing but to date, Xfinity is “not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” the company said in a statement sent to The Associated Press Tuesday.

Xfinity is also requiring customers to reset their passwords, while strongly recommending two-factor or multifactor authentication.

A filing with Maine's office of the attorney general disclosed that nearly 35.9 million people were affected by this breach. The company declined to confirm a specific number Tuesday, but noted the filing's figure represents user IDs.

Philadelphia-based Comcast has more than 32 million broadband customers, according a recent earnings release.

In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed “Citrix Bleed,” has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.

Under new rules that went into effect Monday, the Securities Exchange Commission now requires public companies to disclose all cybersecurity breaches that could affect their bottom lines — within four days of determining a breach is material. As of Tuesday, there were no SEC filings from Comcast about the recent data breach and the company did not immediately address it.

More Stories

Top Stories

01:59
REtrainderrailment41426_2026-04-14-19-14-56

Freight train derailment causes spill, shuts down parts of Route 3 in North Bergen

00:22
REcliftontruckfire_2026-04-14-22-22-44

Fire occurs as tractor-trailer remains logged inside Clifton building

01:41
Dave HX Record Compare

Spring sizzle: Possible record-breaking heat expected on Wednesday

01:50
REjennileoniafire41426_2026-04-14-22-24-21

Leonia considers lithium-ion-battery restrictions after e-scooter fire

01:45
REchristrentonshoting41426_2026-04-14-17-36-53

5 people shot in Trenton in the last week, including 1 fatal

00:58
Wright

Exclusive: Energy Secretary Chris Wright discusses the future of tri-state power, gas prices and the AI surge

01:22
7bb683e9-4a2d-422d-bf18-f0c7433b73d7

Record-breaking heat expected across the tri-state Wednesday

00:40
RTNJJerseyProud04142026VO10pm_2026-04-14-22-20-38

Jersey Proud: Berkeley Heights teen pulls of 'prom-posal' on friend who works for rescue squad

00:56
MTNJTransitWorldCup0414_2026-04-14-22-29-15

Round-trip NJ Transit tickets to MetLife during World Cup will reportedly cost $100 or more

01:56
Image (60)

New Jersey reacts to ‘New York - New Jersey Stadium’ branding ahead of 2026 World Cup

01:28
Murdoch5pBeachPKG_2026-04-14-17-27-52

Summer-like temperatures draw big crowds down the Shore

JANKOWSKI BLURRED

Garfield man tried to lure 2 children into his vehicle, prosecutor says

AP25093446309505

Springsteen, Bon Jovi among stars set for two-night concert at Monmouth University celebrating America’s 250th birthday

FATAL CAR ACCIDENT

Manchester man charged in crash that killed Freehold woman, authorities say

00:27
Keansburg St. Patrick's Day Parade

College fire safety officer arrested in incident that prompted cancellation of Keansburg parade

Police LIghts

Man fatally shoots estranged wife at rehab facility before killing himself, authorities say

Gregg Page

Philly man faces 50 years for deadly Atlantic City shooting

00:28
Screenshot 2026-04-14 074111

Did you see it? SpaceX launch visible over parts of NJ this morning

00:28
4142026NJtrump_2026-04-14-07-23-16

Cardinal Tobin calls Trump AI image as Jesus deeply offensive to millions of believers

App StoreGoogle Play Store

info

Newsletter

Send Photos/Videos

Contact

About Us

News Team

News 12 New York

follow us

Twitter

Facebook

Instagram

more resources

Optimum Corporate

Optimum Service

Advertise on News 12

Careers

Content Removal Policy

© 2026 N12N, LLC

Privacy Policy

Terms of Service

Ad Choices