Current:Home > NewsXfinity hack affects nearly 36 million customers. Here's what to know. -AssetPath
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-19 00:56:22
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (72827)
Related
- Louvre will undergo expansion and restoration project, Macron says
- Russian foreign minister lambastes the West but barely mentions Ukraine in UN speech
- California governor vetoes bill requiring custody courts to weigh affirmation of gender identity
- Canadian police officer slain, two officers injured while serving arrest warrant in Vancouver suburb
- Will the 'Yellowstone' finale be the last episode? What we know about Season 6, spinoffs
- Oklahoma judge arrested in Austin, Texas, accused of shooting parked cars, rear-ending another
- India-Canada tensions shine light on complexities of Sikh activism in the diaspora
- Workers exit GM facilities targeted as expanded UAW strikes get underway
- Trump wants to turn the clock on daylight saving time
- One Kosovo police officer killed and another wounded in an attack in the north, raising tensions
Ranking
- Jorge Ramos reveals his final day with 'Noticiero Univision': 'It's been quite a ride'
- Salt water wedge in the Mississippi River threatens drinking water in Louisiana
- Dead body, 13-foot alligator found in Florida waterway, officials say
- 'All about fun': Louisiana man says decapitated Jesus Halloween display has led to harassment
- Residents worried after ceiling cracks appear following reroofing works at Jalan Tenaga HDB blocks
- Back in full force, UN General Assembly shows how the most important diplomatic work is face to face
- Vaccines are still tested with horseshoe crab blood. The industry is finally changing
- How North Carolina farmers are selling their grapes for more than a dollar per grape
Recommendation
Newly elected West Virginia lawmaker arrested and accused of making terroristic threats
A study of this champion's heart helped prove the benefits of exercise
Mid-Atlantic coast under flood warnings as Ophelia weakens to post-tropical low and moves north
A black market, a currency crisis, and a tango competition in Argentina
Trump issues order to ban transgender troops from serving openly in the military
Horoscopes Today, September 22, 2023
Natalia Bryant Makes Her Runway Debut at Milan Fashion Week
These Best-Selling, Top-Rated Amazon Bodysuits Are All $25 & Under