Current:Home > reviewsXfinity hack affects nearly 36 million customers. Here's what to know. -TradeBridge
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-18 03:35:59
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (17)
Related
- 'We're reborn!' Gazans express joy at returning home to north
- Alaska report details 280 missing Indigenous people, including whether disappearances are suspicious
- Steve Harvey and Wife Marjorie Call Out Foolishness and Lies Amid Claims She Cheated on Him
- NASCAR driver Ryan Preece released from hospital after terrifying crash
- Woman dies after Singapore family of 3 gets into accident in Taiwan
- 1 dead after a driver and biker group exchange gunfire in road rage dispute near Independence Hall
- Judge sets March 2024 trial date in Trump's federal case related to 2020 election
- Florida prays Idalia won’t join long list of destructive storms with names starting with “I.”
- Meta releases AI model to enhance Metaverse experience
- NHL offseason grades: Pittsburgh Penguins, Toronto Maple Leafs make the biggest news
Ranking
- Grammy nominee Teddy Swims on love, growth and embracing change
- Police in Ohio fatally shot a pregnant shoplifting suspect
- Hawaii power utility takes responsibility for first fire on Maui, but faults county firefighters
- Democratic nominee for Mississippi secretary of state withdraws campaign amid health issues
- The FBI should have done more to collect intelligence before the Capitol riot, watchdog finds
- Alabama presses effort to execute inmate by having him breathe pure nitrogen. And the inmate agrees.
- Miley Cyrus says she and dad Billy Ray Cyrus have 'wildly different' relationships to fame
- Cause of death revealed for star U.S. swimmer Jamie Cail in Virgin Islands
Recommendation
Krispy Kreme offers a free dozen Grinch green doughnuts: When to get the deal
Republican lawyer, ex-university instructor stabbed to death in New Hampshire home, authorities say
Trump trial set for March 4, 2024, in federal case charging him with plotting to overturn election
ACLU sues over Indiana law blocking gender-affirming surgery for inmates
Taylor Swift makes surprise visit to Kansas City children’s hospital
Jennifer Love Hewitt Looks Unrecognizable With New Hair Transformation
Get $30 off These Franco Sarto Lug Sole Loafers Just in Time for Fall
NASCAR driver Ryan Preece released from hospital after terrifying crash