Technology

Comcast confirms hackers stole data of close to 36 million Xfinity customers

Reports have confirmed that Comcast has officially acknowledged a security breach that exposed sensitive information of nearly 36 million Xfinity customers. According to Tech Crunch, the breach stemmed from the exploitation of the "CitrixBleed" vulnerability, a critical-rated security flaw affecting Citrix networking devices commonly used by major corporations. Hackers had been leveraging this vulnerability since

Comcast Retail Experience

Comcast Retail Experience

Share
Picture: Business Wire
Advertisement

Reports have confirmed that Comcast has officially acknowledged a security breach that exposed sensitive information of nearly 36 million Xfinity customers.

According to Tech Crunch, the breach stemmed from the exploitation of the “CitrixBleed” vulnerability, a critical-rated security flaw affecting Citrix networking devices commonly used by major corporations. Hackers had been leveraging this vulnerability since late August, targeting prominent entities such as Boeing, the Industrial and Commercial Bank of China, and law firm Allen & Overy.

Xfinity, the cable television and internet division of Comcast, fell victim to CitrixBleed, with hackers gaining access to internal systems from October 16 to October 19. However, Comcast only detected the malicious activity on October 25. By November 16, it was determined that hackers likely acquired information, including usernames and hashed passwords, which are stored in an unreadable format. The breach also potentially exposed names, contact details, dates of birth, the last four digits of Social Security numbers, and security questions and answers for an unspecified number of customers.

While the notice did not disclose the exact number of impacted customers, a filing with Maine’s attorney general confirmed that nearly 35.8 million customers were affected. Comcast’s broader customer base, as per its latest earnings report, indicates that most, if not all, Xfinity customers were impacted.

As of now, it remains unclear whether a ransom demand was made, the extent of the incident’s impact on Comcast’s operations, or whether the breach has been reported to the U.S. Securities and Exchange Commission in compliance with data breach reporting rules. Comcast is urging affected customers to reset their passwords and is recommending the adoption of two-factor or multi-factor authentication, which is not mandatory by default for all customer accounts. Comcast spokesperson Joel Shadle stated that there is no evidence of customer data being leaked or attacks on customers, and data analysis is ongoing to identify potential additional types of accessed information.

TechnologyAfrican startups
Greg Stewart

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Africa is getting more Big Tech investment, but the basics are still holding it back
Read nextTechnology

Africa is getting more Big Tech investment, but the basics are still holding it back

Google, Meta, Microsoft, Amazon and Starlink are putting more money into Africa's digital infrastructure. Subsea cables are reaching more parts of the continent, satellite internet is expanding and cloud companies are adding services for African customers. For businesses that have spent years dealing with unreliable connections, that is useful. There is still a problem underneath

Vutomi Manzini · 4 min readContinue reading