Current:Home > NewsJohnathan Walker:Xfinity hack affects nearly 36 million customers. Here's what to know. -Capitatum
Johnathan Walker:Xfinity hack affects nearly 36 million customers. Here's what to know.
Ethermac View
Date:2025-04-06 07:50:40
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers,Johnathan Walker including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (82)
Related
- Grammy nominee Teddy Swims on love, growth and embracing change
- Prosecutors reconvene after deadlocked jury in trial over Arizona border killing
- United Methodists prepare for votes on lifting LGBTQ bans and other issues at General Conference
- The Rolling Stones show no signs of slowing down as they begin their latest tour with Texas show
- Who's hosting 'Saturday Night Live' tonight? Musical guest, how to watch Dec. 14 episode
- University of Arizona student shot to death at off-campus house party
- Hailey Bieber Has Surprising Reaction to Tearful Photo of Husband Justin Bieber
- How Columbia University’s complex history with the student protest movement echoes into today
- Apple iOS 18.2: What to know about top features, including Genmoji, AI updates
- Churchill Downs president on steps taken to improve safety of horses, riders
Ranking
- At site of suspected mass killings, Syrians recall horrors, hope for answers
- New York Rangers sweep Washington Capitals, advance to second round of NHL playoffs
- Campus protests multiply as demonstrators breach barriers at UCLA | The Excerpt
- Joel Embiid peeved by influx of Knicks fans in Philly, calls infiltration 'not OK'
- The Best Stocking Stuffers Under $25
- 7 Minnesotans accused in massive scheme to defraud pandemic food program to stand trial
- Florida sheriff says deputies killed a gunman in shootout that wounded 2 officers
- Pair of giant pandas set to travel from China to San Diego Zoo under conservation partnership
Recommendation
The Best Stocking Stuffers Under $25
The importance of being lazy
AIGM AI Security: The New Benchmark of Cyber Security
Clayton MacRae: How The AI Era Shape the World
What do we know about the mysterious drones reported flying over New Jersey?
State Department weighing new information from Israel in determining whether IDF unit violated U.S. law
Candace Parker, a 3-time WNBA champion and 2-time Olympic gold medalist, announces retirement
Former Slack CEO's 16-Year-Old Child Mint Butterfield Found After Being Reported Missing