News12 New York
Where to Watch
Download the App
Local
Crime
Weather
beWell
The East End
Crime Files

Xfinity notifies customers of data breach

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

Associated Press

Dec 20, 2023, 7:35 AM

Updated

Share:

More Stories

Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

In a Monday notice to customers, Xfinity said there was unauthorized access to internal systems as a result of this vulnerability — which was previously announced by software provider Citrix — between Oct. 16 and 19.

Xfinity discovered the “suspicious activity” on Oct. 25, and in the following months determined that information was “likely acquired.” On Dec. 6, the company concluded that information included usernames and hashed passwords — and, for some customers, the last four digits of Social Security numbers, account security questions, birthdates and contact information.

Analysis of the breach is still continuing but to date, Xfinity is “not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” the company said in a statement sent to The Associated Press Tuesday.

Xfinity is also requiring customers to reset their passwords, while strongly recommending two-factor or multifactor authentication.

A filing with Maine's office of the attorney general disclosed that nearly 35.9 million people were affected by this breach. The company declined to confirm a specific number Tuesday, but noted the filing's figure represents user IDs.

Philadelphia-based Comcast has more than 32 million broadband customers, according a recent earnings release.

In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed “Citrix Bleed,” has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.

Under new rules that went into effect Monday, the Securities Exchange Commission now requires public companies to disclose all cybersecurity breaches that could affect their bottom lines — within four days of determining a breach is material. As of Tuesday, there were no SEC filings from Comcast about the recent data breach and the company did not immediately address it.

More Stories

Top Stories

01:49
herkimerstmultipleshootingCM_2026-04-16-22-43-09

2 men injured in Ocean Hill shooting; gunman on the run

01:43
FB Rain Day

Overnight shower chances with one more summer-like day for Brooklyn

00:25
82255e38-c1e0-4956-a4fb-0451dea06abb

Body found in water near Shore Road Park in Bay Ridge

01:16
officeronhorsepursuitCM_2026-04-16-22-08-32

NYPD officer on horse chases down purse snatcher in Manhattan

01:51
futureofpachaCM_2026-04-16-22-50-55

New owners of Brooklyn Mirage site, Pacha, hope for fresh start with festivalgoers ahead of June 20 opening date

00:46
sticklibraryfordogsCM_2026-04-16-23-00-16

Free ‘stick library’ pops up in Brooklyn Heights for dog owners

00:38
carjacking1030pZC_2026-04-16-22-46-50

Carjacking chaos unfolds in Mill Basin: 72-year-old woman in walker struck, another knocked to the ground

02:29
Screenshot 2026-04-16 184319

Advocates rally for ‘Priscilla’s Law,’ calling for stricter e-bike regulations in NYC

01:51
Screenshot 2026-04-16 193429

DOE employee accused of dropping 10-year-old boy at Brownsville school

01:46
Screenshot 2026-04-16 191353

‘He won’t get pardoned from God.’ Family of East New York shooting victim speaks to News 12

01:58
Screenshot 2026-04-16 192310

Mayor Mamdani follows through on plan to tax the rich

01:43
Screenshot 2026-04-16 190101

Gravesend NYCHA tenants demand ADA-accessible ramps

Murder Sentencing

Three men sentenced in murder of security guard

00:32
citysueslandlordCM_2026-04-16-22-08-45

New York City sues landlord over alleged short term rental scheme

00:32
416BKelderscam_2026-04-16-06-35-33

Scammer impersonating NYPD employee steals thousands from 92-year-old woman

01:41
416edricnoongymthefts_2026-04-16-12-33-20

Thefts reported at Bushwick Planet Fitness; police release images of person wanted

00:33
BX12PMBODEGACATS_2026-04-16-12-14-21

Paws off bodega cats: New bill could remove city's prohibition on cats in retail food stores

00:21
michelin star restaurants

Michelin Guide adds five new Brooklyn restaurants to its star list

02:11
VIOLENTARRESTAB530PM_2026-04-15-17-35-41

NYPD: Officers' badge, guns removed following chaotic arrest inside Boerum Hill Liquor store

01:45
crownheightsstabbing1030pZC_2026-04-15-22-39-25

Man stabbed in the back in Crown Heights steps from fatal attack the night before

App StoreGoogle Play Store

info

Newsletter

Send Photos/Videos

Contact

About Us

News Team

News 12 New York

follow us

Twitter

Facebook

Instagram

more resources

Optimum Corporate

Optimum Service

Advertise on News 12

Careers

Content Removal Policy

© 2026 N12N, LLC

Privacy Policy

Terms of Service

Ad Choices