Current:Home > MarketsXfinity hack affects nearly 36 million customers. Here's what to know. -BeyondProfit Compass
Xfinity hack affects nearly 36 million customers. Here's what to know.
SignalHub Quantitative Think Tank Center View
Date:2025-04-11 11:43:12
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (6)
Related
- Travis Hunter, the 2
- The Supreme Court took powers away from federal regulators. Do California rules offer a backstop?
- Minnesota trooper accused of driving 135 mph before crash that killed teen
- A gunman killed at a Yellowstone dining facility earlier told a woman he planned a mass shooting
- How to watch the 'Blue Bloods' Season 14 finale: Final episode premiere date, cast
- Spain's Álvaro Morata faces Euro 2024 fitness worry after postgame incident
- Missouri man accused of imprisoning and torturing a woman for weeks indicted for murder
- Opening statements to give roadmap to involuntary manslaughter case against Alec Baldwin
- South Korean president's party divided over defiant martial law speech
- Carol Bongiovi, Jon Bon Jovi's mother, dies at 83
Ranking
- Why members of two of EPA's influential science advisory committees were let go
- Alex De Minaur pulls out of Wimbledon quarterfinal match vs. Novak Djokovic
- Philadelphia won’t seek death penalty in Temple U. officer’s death. Colleagues and family are upset
- Wrongful death lawsuit against West Virginia state troopers settled in Maryland man’s death
- At site of suspected mass killings, Syrians recall horrors, hope for answers
- A gunman killed at a Yellowstone dining facility earlier told a woman he planned a mass shooting
- It is way too hot. 160 million under alert as heat breaks records and a bridge
- What's the best temperature to set your AC on during a summer heat wave?
Recommendation
Are Instagram, Facebook and WhatsApp down? Meta says most issues resolved after outages
TikToker Bella Brave, 10, Placed in a Medically Induced Coma
Armed man fatally shot in gunfire exchange at Yellowstone National Park identified
How the Kansas City Chiefs Are Honoring Cheerleader Krystal Anderson 4 Months After Her Death
Residents worried after ceiling cracks appear following reroofing works at Jalan Tenaga HDB blocks
Congressional Democrats meet amid simmering concerns over Biden reelection
Relive Every Sweet Moment of Alexis Bellino and John Janssen's Whirlwind Romance
Delta partners with startup Riyadh Air as it plans to offer flights to Saudi Arabia