Comcast Xfinity breach exposed data of 35.8 million customers via Citrix Bleed
- Organization
- Comcast Xfinity
- Exploit
- Hacking
- Industry
- Telecommunications
Comcast disclosed in mid-December 2023 that intruders had reached internal Xfinity systems two months earlier by exploiting CVE-2023-4966, the Citrix NetScaler flaw widely known as Citrix Bleed. The company said unauthorized access occurred between October 16 and October 19, 2023, shortly after Citrix issued its patch and before Comcast applied the additional mitigation guidance the vendor published on October 23.
Xfinity said it identified suspicious activity during a routine security review on October 25 and concluded on November 16 that data had probably been taken. By December 6 it had determined what the stolen files contained.
The notice put the number of affected customers at more than 35.8 million. Cybersecurity Dive reported the figure as approximately 35.9 million. Exposed records included Xfinity usernames and hashed passwords. For an unspecified subset of customers the data also included names, contact details, the last four digits of Social Security numbers, dates of birth, and secret questions with their answers.
Comcast notified federal law enforcement, required affected customers to reset their passwords and urged them to enable two-factor or multi-factor authentication. The company said it had no indication at the time that the stolen data had been used fraudulently. Citrix Bleed had been exploited as a zero day since late August 2023 and was used against many organizations after the patch became available.