Current:Home > FinanceXfinity hack affects nearly 36 million customers. Here's what to know. -DollarDynamic
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-20 22:59:42
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (5)
Related
- Finally, good retirement news! Southwest pilots' plan is a bright spot, experts say
- Men who say they were abused by a Japanese boy band producer criticize the company’s response
- Texas jeweler and dog killed in targeted hit involving son, daughter-in-law
- After Iowa caucuses, DeSantis to go to South Carolina first in a jab at Haley
- The White House is cracking down on overdraft fees
- Why Margot Robbie Feels So Lucky to Be Married to Normie Tom Ackerley
- Iran sentences imprisoned Nobel laureate Narges Mohammadi to an additional prison term
- How Tyre Nichols' parents stood strong in their public grief in year after fatal police beating
- 2025 'Doomsday Clock': This is how close we are to self
- Live updates | Gaza death toll tops 24,000 as Israel strikes targets in north and south
Ranking
- Paris Hilton, Nicole Richie return for an 'Encore,' reminisce about 'The Simple Life'
- Pope says he hopes to keep promise to visit native Argentina for first time since becoming pontiff
- Iran sentences imprisoned Nobel laureate Narges Mohammadi to an additional prison term
- Longest playoff win droughts in NFL: Dolphins, Raiders haven't won in postseason in decades
- Sonya Massey's father decries possible release of former deputy charged with her death
- Colombia landslide kills at least 33, officials say
- MLK Day 2024: How did Martin Luther King Jr. Day become a federal holiday? What to know
- Former high-ranking Philadelphia police commander to be reinstated after arbitrator’s ruling
Recommendation
Why members of two of EPA's influential science advisory committees were let go
4 dead, 1 critically hurt in Arizona hot air balloon crash
Philippine president congratulates Taiwan’s president-elect, strongly opposed by China
Phoenix police shoot, run over man they mistake for domestic violence suspect
House passes bill to add 66 new federal judgeships, but prospects murky after Biden veto threat
A Cambodian court convicts activists for teaching about class differences, suspends their jail terms
Rex Heuermann, suspect in Gilgo Beach serial killings, expected to be charged in 4th murder, sources say
Turkish strikes on infrastructure facilities wound 10 and cut off power in areas in northeast Syria