Current:Home > InvestXfinity hack affects nearly 36 million customers. Here's what to know. -Aspire Financial Strategies
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-11 16:52:26
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (5734)
Related
- The Daily Money: Spending more on holiday travel?
- Illinois’ top court says odor of burnt marijuana isn’t enough to search car
- Board approves more non-lethal weapons for UCLA police after Israel-Hamas war protests
- Postal Service chief frustrated at criticism, but promises ‘heroic’ effort to deliver mail ballots
- Juan Soto to be introduced by Mets at Citi Field after striking record $765 million, 15
- Josh Heupel's rise at Tennessee born out of Oklahoma firing that was blessing in disguise
- Justice Department opens civil rights probe into sheriff’s office after torture of 2 Black men
- A couple found the Kentucky highway shooter’s remains by being bounty hunters for a week, they say
- Opinion: Gianni Infantino, FIFA sell souls and 2034 World Cup for Saudi Arabia's billions
- A new life is proposed for Three Mile Island supplying power to Microsoft data centers
Ranking
- 'Malcolm in the Middle’ to return with new episodes featuring Frankie Muniz
- Takeaways from AP’s report on churches starting schools in voucher states
- Rare G.K. Chesterton essay on mystery writing is itself a mystery
- Who is Arch Manning? Texas names QB1 for Week 4 as Ewers recovers from injury
- Federal hiring is about to get the Trump treatment
- ‘Some friends say I’m crazy': After school shooting, gun owners rethink Georgia's laws
- WNBA playoffs bracket: Final standings, seeds, matchups, first round schedule
- 'SNL' taps Ariana Grande, Chappell Roan, Billie Eilish, John Mulaney for Season 50 lineup
Recommendation
Apple iOS 18.2: What to know about top features, including Genmoji, AI updates
Senator’s son to appear in court to change plea in North Dakota deputy’s crash death
Georgia jobless rate rises for a fourth month in August
A couple found the Kentucky highway shooter’s remains by being bounty hunters for a week, they say
'Squid Game' without subtitles? Duolingo, Netflix encourage fans to learn Korean
Detroit Red Wings, Moritz Seider agree to 7-year deal worth $8.55 million per season
North Carolina Republican governor candidate Mark Robinson vows to stay in race despite media report
US troops finish deployment to remote Alaska island amid spike in Russian military activity