Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

In a Monday notice to customers, Xfinity said there was unauthorized access to internal systems as a result of this vulnerability — which was previously announced by software provider Citrix — between Oct. 16 and 19.

Xfinity discovered the “suspicious activity” on Oct. 25, and in the following months determined that information was “likely acquired.” On Dec. 6, the company concluded that information included usernames and hashed passwords — and, for some customers, the last four digits of Social Security numbers, account security questions, birthdates and contact information.

Analysis of the breach is still continuing but to date, Xfinity is “not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” the company said in a statement sent to The Associated Press Tuesday.

Xfinity is also requiring customers to reset their passwords, while strongly recommending two-factor or multifactor authentication.

A filing with Maine's office of the attorney general disclosed that nearly 35.9 million people were affected by this breach. The company declined to confirm a specific number Tuesday, but noted the filing's figure represents user IDs.

Philadelphia-based Comcast has more than 32 million broadband customers, according a recent earnings release.

In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed “Citrix Bleed,” has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.

Under new rules that went into effect Monday, the Securities Exchange Commission now requires public companies to disclose all cybersecurity breaches that could affect their bottom lines — within four days of determining a breach is material. As of Tuesday, there were no SEC filings from Comcast about the recent data breach and the company did not immediately address it.

Share:
More In Business
State Department Halts Plan to buy $400M of Armored Tesla Vehicles
The State Department had been in talks with Elon Musk’s Tesla company to buy armored electric vehicles, but the plans have been put on hold by the Trump administration after reports emerged about a potential $400 million purchase. A State Department spokesperson said the electric car company owned by Musk was the only one that expressed interest back in May 2024. The deal with Tesla was only in its planning phases but it was forecast to be the largest contract of the year. It shows how some of his wealth has come and was still expected to come from taxpayers.
Goodyear Blimp at 100: ‘Floating Piece of Americana’ Still Thriving
At 100 years old, the Goodyear Blimp is an ageless star in the sky. The 246-foot-long airship will be in the background of the Daytona 500 — flying roughly 1,500 feet above Daytona International Speedway, actually — to celebrate its greatest anniversary tour. Even though remote camera technologies are improving regularly and changing the landscape of aerial footage, the blimp continues to carve out a niche. At Daytona, with the usual 40-car field racing around a 2½-mile superspeedway, views from the blimp aptly provide the scope of the event.
Is U.S. Restaurants’ Breakfast Boom Contributing to High Egg Prices?
It’s a chicken-and-egg problem: Restaurants are struggling with record-high U.S. egg prices, but their omelets, scrambles and huevos rancheros may be part of the problem. Breakfast is booming at U.S. eateries. First Watch, a restaurant chain that serves breakfast, brunch and lunch, nearly quadrupled its locations over the past decade to 570. Fast-food chains like Starbucks and Wendy's added more egg-filled breakfast items. In normal times, egg producers could meet the demand. But a bird flu outbreak that has forced them to slaughter their flocks is making supplies scarcer and pushing up prices. Some restaurants like Waffle House have added a surcharge to offset their costs.
Trump Administration Shutters Consumer Protection Agency
The Trump administration has ordered the Consumer Financial Protection Bureau to stop nearly all its work, effectively shutting down the agency that was created to protect consumers after the 2008 financial crisis and subprime mortgage-lending scandal. Russell Vought is the newly installed director of the Office of Management and Budget. Vought directed the CFPB in a Saturday night email to stop work on proposed rules, to suspend the effective dates on any rules that were finalized but not yet effective, and to stop investigative work and not begin any new investigations. The agency has been a target of conservatives since President Barack Obama created it following the 2007-2008 financial crisis.
Load More