Current:Home > reviewsXfinity hack affects nearly 36 million customers. Here's what to know. -USAMarket
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-13 13:22:36
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (885)
Related
- Justice Department, Louisville reach deal after probe prompted by Breonna Taylor killing
- Kelly Osbourne Reveals She’s Changing Son Sidney’s Last Name After “Biggest Fight” With Sid Wilson
- 2024 NFL draft: Ohio State's Marvin Harrison Jr. leads top 5 wide receiver prospect list
- In today's global migrant crisis, echoes of Dorothea Lange's American photos
- Juan Soto praise of Mets' future a tough sight for Yankees, but World Series goal remains
- Jam Master Jay killing: Men convicted of murder nearly 22 years after Run-DMC's rapper's death
- These Survivor Secrets Reveal How the Series Managed to Outwit, Outplay, Outlast the Competition
- Funeral of Russian opposition leader Alexei Navalny to be held on Friday, his spokesperson says
- Working Well: When holidays present rude customers, taking breaks and the high road preserve peace
- Jury finds 2 men guilty on all counts in Jam Master Jay murder trial
Ranking
- 'No Good Deed': Who's the killer in the Netflix comedy? And will there be a Season 2?
- A new Wendy Williams documentary raises more questions than it answers
- Adele postpones March dates of Las Vegas residency, goes on vocal rest: 'Doctor's orders'
- Is Uber-style surge pricing coming to fast food? Wendy's latest move offers a clue.
- McConnell absent from Senate on Thursday as he recovers from fall in Capitol
- Louisiana moves closer to final passage of tough-on-crime bills that could overhaul justice system
- Wear the New Elegant Casual Trend with These Chic & Relaxed Clothing Picks
- See the full 'Dune: Part Two' cast: Who plays Paul, Chani, Feyd-Rautha Harkonnen in 2024 sequel?
Recommendation
Apple iOS 18.2: What to know about top features, including Genmoji, AI updates
How long does it take to boil corn on the cob? A guide to perfectly cook the veggie
FBI, state investigators seek tips about explosive left outside Alabama attorney general’s office
These Survivor Secrets Reveal How the Series Managed to Outwit, Outplay, Outlast the Competition
Bill Belichick's salary at North Carolina: School releases football coach's contract details
The 61 Most Popular Amazon Items E! Readers Bought This Month- $1 Lipstick, Olivia Culpo's Picks & More
Expanding wildfires force Texas nuclear facility to pause operations
Fans briefly forced to evacuate Assembly Hall during Indiana basketball game vs. Wisconsin