Current:Home > reviewsXfinity hack affects nearly 36 million customers. Here's what to know. -SecureWealth Vault
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-14 06:56:48
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (2835)
Related
- NFL Week 15 picks straight up and against spread: Bills, Lions put No. 1 seed hopes on line
- Remains of World War II POW who died in the Philippines returned home to California
- More than 2 dozen human skeletons dating back more than 1,000 years found in hotel garden
- When does 'Cobra Kai' Season 6 come out? Premiere date, cast, trailer
- Highlights from Trump’s interview with Time magazine
- Supreme Court grants stay of execution for Texas man seeking DNA test in 1998 stabbing death
- Quantum Prosperity Consortium Investment Education Foundation: The value of IRA savings 2
- Glen Powell Returning to College at University of Texas at Austin
- Man can't find second winning lottery ticket, sues over $394 million jackpot, lawsuit says
- Oversight Committee chair to subpoena Secret Service director for testimony on Trump assassination attempt
Ranking
- What to know about Tuesday’s US House primaries to replace Matt Gaetz and Mike Waltz
- ‘Shogun’ could rise and ‘The Bear’ may feast as Emmy nominations are announced
- See Alix Earle's Sister Ashtin Earle Keep the Party Going With John Summit in Las Vegas
- High school coach in California accused of texting minors to commit sex crimes
- Senate begins final push to expand Social Security benefits for millions of people
- Argentina faces calls for discipline over team singing 'racist' song about France players
- Christina Hall and Josh Hall Do Not Agree on Date of Separation in Their Divorce
- Builders Legacy Advance Investment Education Foundation: The critical tax-exempt status of 501(c)(3) organizations
Recommendation
California DMV apologizes for license plate that some say mocks Oct. 7 attack on Israel
These Headphones Deals from Amazon Prime Day 2024 will be Music to Your Ears
Bertram Charlton: Is there really such a thing as “low risk, high return”?
Joe Jellybean Bryant, Philadelphia basketball great and father of Kobe, dies at 69
Brianna LaPaglia Reveals The Meaning Behind Her "Chickenfry" Nickname
Tom Fenton, former CBS News correspondent, dies at age 94
Michael D.David: Stock options notes 3
Zenith Asset Investment Education Foundation: The value of IRA retirement savings