Current:Home > MyXfinity hack affects nearly 36 million customers. Here's what to know. -WorldMoney
Xfinity hack affects nearly 36 million customers. Here's what to know.
View
Date:2025-04-18 07:14:09
A security breach at Comcast-owned Xfinity has exposed the personal data of nearly all the internet provider's customers, including account usernames, passwords and answers to their security questions.
Comcast said in a filing with Maine's attorney general's office that the hack affected 35.8 million people, with the media and technology giant notifying customers of the attack through its website and by email, the company said Monday. The intrusion stems from a vulnerability in software from cloud computing company Citrix, according to Comcast.
Although Citrix patched the vulnerability in October, Xfinity learned that unauthorized users gained access to its internal systems between Oct. 16 and Oct. 19, revealing customer data. For some people, that included their names, contact information, account usernames and passwords, birthdates, parts of their Social Security numbers and answers to their security questions.
In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed "Citrix Bleed," has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.
Under new federal rules that took effect Monday, the Securities Exchange Commission requires public companies to disclose all cybersecurity breaches that could affect their financial results within four days of determining a breach is material.
What should I do if I'm an Xfinity customer?
All Xfinity customers — even those whose accounts might not have been breached — must reset their usernames and passwords, according to Comcast. Xfinity is also encouraging subscribers to use two-factor authentication to secure their accounts.
"While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question," Comcast noted.
Comcast has more than 32 million broadband customers, according to its most recent earnings report, suggesting that the breach likely affected all Xfinity customers.
Customers with questions can contact Xfinity toll-free at (888) 799-2560 24 hours a day Monday through Friday from 9 a.m. to 9 p.m. Eastern time. More information is available on Xfinity's website at xfinity.com/dataincident.
—The Associated Press contributed to this report.
- In:
- Technology
- Consumer News
- Security Hacker
- Xfinity
- Data Breach
- Comcast
- Computers
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News streaming to discuss her reporting.
veryGood! (1)
Related
- Civic engagement nonprofits say democracy needs support in between big elections. Do funders agree?
- UN nuclear agency team watches Japanese lab workers prepare fish samples from damaged nuclear plant
- Research by Public Health Experts Shows ‘Damning’ Evidence on the Harms of Fracking
- 5 Things podcast: Why are many Americans still stressed about their finances?
- Warm inflation data keep S&P 500, Dow, Nasdaq under wraps before Fed meeting next week
- Teachers union in Portland, Oregon, votes to strike over class sizes, pay, lack of resources
- He was rejected by 14 colleges. Then Google hired him.
- High mortgage rates push home sales decline, tracking to hit Great Recession levels
- Juan Soto praise of Mets' future a tough sight for Yankees, but World Series goal remains
- 'The Golden Bachelor' recap: A faked injury, a steamy hot tub affair and a feud squashed
Ranking
- California DMV apologizes for license plate that some say mocks Oct. 7 attack on Israel
- Greek economy wins new vote of confidence with credit rating upgrade and hopes for investment boost
- Hilton hotel in Texas cancels Palestinian rights group's conference, citing safety concerns
- The 10 Best Sales to Shop This Weekend: Wayfair, Ulta, J.Crew Factory, Calpak, Kate Spade & More
- Buckingham Palace staff under investigation for 'bar brawl'
- The Republicans who opposed Jim Jordan on the third ballot — including 3 new votes against him
- Georgia prison escapees still on the lam after fleeing Bibb County facility: What to know
- State Department issues worldwide caution alert for U.S. citizens due to Israel-Hamas war
Recommendation
Nearly half of US teens are online ‘constantly,’ Pew report finds
Andre Iguodala, the 2015 NBA Finals MVP, announces retirement after 19 seasons
You're not imagining it —'nudity creep' in streaming TV reveals more of its stars
Man gets 13-year sentence for stabbings on Rail Runner train in Albuquerque
What do we know about the mysterious drones reported flying over New Jersey?
Questions linger after Connecticut police officers fatally shoot man in his bed
Northern Europe continues to brace for gale-force winds and floods
Spirit Airlines cancels dozens of flights to inspect some of its planes. Disruptions will last days