Current:Home > ScamsXfinity hack affects nearly 36 million customers. Here's what to know. -Legacy Profit Partners
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-16 16:25:16
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (2)
Related
- Why Sean "Diddy" Combs Is Being Given a Laptop in Jail Amid Witness Intimidation Fears
- The 15 most valuable old toys that you might have in your attic (but probably don’t)
- Tesla’s Swedish labor dispute pits anti-union Musk against Scandinavian worker ideals
- Disney+'s 'Percy Jackson' series is more half baked than half-blood: Review
- The FBI should have done more to collect intelligence before the Capitol riot, watchdog finds
- A month after House GOP's highly touted announcement of release of Jan. 6 videos, about 0.4% of the videos have been posted online
- If You Don’t Have Time for Holiday Shopping, These Gift Cards Are Great Last-Minute Presents
- Consider this before you hang outdoor Christmas lights: It could make your house a target
- Gen. Mark Milley's security detail and security clearance revoked, Pentagon says
- New tower at surfing venue in Tahiti blowing up again as problem issue for Paris Olympic organizers
Ranking
- The FTC says 'gamified' online job scams by WhatsApp and text on the rise. What to know.
- DNA may link Philadelphia man accused of slashing people on trail to a cold-case killing, police say
- 93-year-old vet missed Christmas cards. Now he's got more than 600, from strangers nationwide.
- As 'The Crown' ends, Imelda Staunton tells NPR that 'the experiment paid off'
- Meta donates $1 million to Trump’s inauguration fund
- Christian group and family raise outcry over detention of another ‘house church’ elder in China
- Nature groups go to court in Greece over a strategic gas terminal backed by the European Union
- Humblest Christmas tree in the world sells for more than $4,000 at auction
Recommendation
Meta releases AI model to enhance Metaverse experience
Homicide victim found dead in 1979 near Las Vegas Strip ID’d as missing 19-year-old from Cincinnati
New 'Washington Post' CEO accused of Murdoch tabloid hacking cover-up
Find Your Signature Scent at Sephora's Major Perfume Sale, Here Are 8 E! Shopping Editors Favorites
Federal appeals court upholds $14.25 million fine against Exxon for pollution in Texas
93-year-old vet missed Christmas cards. Now he's got more than 600, from strangers nationwide.
How UPS is using A.I. to fight against package thefts
Neighbors describe frantic effort to enter burning Arizona home where 5 kids died: Screaming at the tops of our lungs