Comcast Xfinity data breach affects over 35 million people

From The Verge: Comcast is notifying Xfinity customers of a “data security incident” it says resulted in the theft of customer information, including usernames, passwords, contact information, partial social security numbers, and more. In a notice on Monday, Xfinity said “there was unauthorized access” to its systems from October 16th to October 19th, 2023.

BleepingComputer linked this breach notice published in the state of Maine, which shows the total number of people affected by the breach is 35,879,455, including over 50,000 people in Maine.

Xfinity traces the breach to a security vulnerability disclosed by cloud computing company Citrix, which began alerting customers about a flaw in software Xfinity and other companies use on October 10th. While Xfinity now says it patched the security hole, it later uncovered suspicious activity on its internal systems “that was concluded to be a result of this vulnerability.”

The report from BleepingComputer also notes Citrix released a notification of the vulnerability (now known as “Citrix Bleed”) nearly two weeks earlier, on October 10th, telling customers to patch as soon as possible, although it had not noted active exploitation of the flaw. However, by October 18th, the security researchers at Mandiant reported it was under “active” exploitation, and on October 23rd, a Citrix blog post said it was aware of targeted attacks.

View: Full Article