Current:Home > MyXfinity hack affects nearly 36 million customers. Here's what to know. -StockSource
Xfinity hack affects nearly 36 million customers. Here's what to know.
Will Sage Astor View
Date:2025-04-10 09:51:05
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (356)
Related
- Stamford Road collision sends motorcyclist flying; driver arrested
- Johnny Bananas and Other Challenge Stars Reveal Why the Victory Means More Than the Cash Prize
- Election officials keep Green Party presidential candidate on Wisconsin ballot
- Woman arrested, charged in Elvis Presley Graceland foreclosure scheme
- Former longtime South Carolina congressman John Spratt dies at 82
- Greenidge Sues New York State Environmental Regulators, Seeking to Continue Operating Its Dresden Power Plant
- Texas Rodeo Roper Ace Patton Ashford Dead at 18 After Getting Dragged by Horse
- Stranded Astronauts Butch Wilmore and Suni Williams' Families Weigh in on Their Status
- What do we know about the mysterious drones reported flying over New Jersey?
- Caitlin Clark scores 29 to help Fever fend off furious Mercury rally in 98-89 win
Ranking
- Behind on your annual reading goal? Books under 200 pages to read before 2024 ends
- Lawsuit: Kansas school employee locked teen with Down syndrome in closet, storage cage
- Ukrainian forces left a path of destruction in the Kursk operation. AP visited a seized Russian town
- Alligators and swamp buggies: How a roadside attraction in Orlando staved off extinction
- Intellectuals vs. The Internet
- Caitlin Clark returns to action Sunday: How to watch Fever vs. Storm
- Extreme heat at Colorado airshow sickens about 100 people with 10 hospitalized, officials say
- Her name was on a signature petition to be a Cornel West elector. Her question: What’s an elector?
Recommendation
The company planning a successor to Concorde makes its first supersonic test
French actor and heartthrob Alain Delon dies at 88
Hundreds of miles away, Hurricane Ernesto still affects US beaches with rip currents, house collapse
Hundreds of miles away, Hurricane Ernesto still affects US beaches with rip currents, house collapse
Macy's says employee who allegedly hid $150 million in expenses had no major 'impact'
Jailed Chinese activist faces another birthday alone in a cell, his wife says
College football begins next weekend with No. 10 Florida State facing Georgia Tech in Ireland
Taylor Swift shows off a new 'Midnights' bodysuit in Wembley