Current:Home > MyXfinity hack affects nearly 36 million customers. Here's what to know. -FundSphere
Xfinity hack affects nearly 36 million customers. Here's what to know.
TradeEdge View
Date:2025-04-10 12:34:50
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (544)
Related
- Plunge Into These Olympic Artistic Swimmers’ Hair and Makeup Secrets
- Wisconsin elections official claims he’s done more for Black community than any white Republican
- Climate scientist Michael Mann wins defamation suit over comparison to molester, jury decides
- NYC vigilantes 'Guardian Angels' tackle New Yorker on live TV, misidentify him as migrant
- The 401(k) millionaires club keeps growing. We'll tell you how to join.
- Dakota Johnson says being on 'The Office' was 'the worst time of my life'
- Khloe Kardashian Shows Off Son Tatum Thompson’s Growth Spurt in New Photos
- Gov. Shapiro seeks school-funding boost to help poorer districts, but Republicans remain wary
- Working Well: When holidays present rude customers, taking breaks and the high road preserve peace
- Maryland Gov. Wes Moore outlines a data-driven plan to reach goals for the state
Ranking
- Paris Olympics live updates: Quincy Hall wins 400m thriller; USA women's hoops in action
- The first tornado to hit Wisconsin in February was spotted
- Henry Fambrough, member of Motown group The Spinners, dies at 85
- Ex-prison officer charged in death of psychiatric patient in New Hampshire
- Giants, Lions fined $200K for fights in training camp joint practices
- Sewage Across Borders: The Tijuana River Is Spewing Wastewater Into San Diego Amid Historic Storms, Which Could Threaten Public Health
- Sleepy polar bear that dug out a bed in sea ice to nap wins prestigious wildlife photography award
- NBA trade tracker: Gordon Hayward, Bojan Bogdanovic, Patrick Beverley on the move
Recommendation
USA men's volleyball mourns chance at gold after losing 5-set thriller, will go for bronze
Motorcyclist seen smashing in back of woman’s car pleads guilty to aggravated assault
New Mexico legislators seek endowment to bolster autonomous tribal education programs
A criminal actor is to blame for a dayslong cyberattack on a Chicago hospital, officials say
NCAA hits former Michigan coach Jim Harbaugh with suspension, show-cause for recruiting violations
Stock market today: Tokyo hits 30-year high, with many Asian markets shut for Lunar New Year holiday
Climate scientist Michael Mann wins defamation suit over comparison to molester, jury decides
‘Whistling sound’ heard on previous Boeing Max 9 flight before door plug blowout, lawsuit alleges