The Los Angeles Post
California & Local U.S. World Business Lifestyle
Today: January 15, 2025
Today: January 15, 2025

Xfinity notifies its customers of data breach linked to software vulnerability

Xfinity Data Breach
December 19, 2023
AP - AP

NEW YORK (AP) — Hackers accessed Xfinity customers' personal information by exploiting a vulnerability in software used by the company, the Comcast-owned telecommunications business announced this week.

In a Monday notice to customers, Xfinity said there was unauthorized access to internal systems as a result of this vulnerability — which was previously announced by software provider Citrix — between Oct. 16 and 19.

Xfinity discovered the “suspicious activity” on Oct. 25, and in the following months determined that information was “likely acquired.” On Dec. 6, the company concluded that information included usernames and hashed passwords — and, for some customers, the last four digits of Social Security numbers, account security questions, birthdates and contact information.

Analysis of the breach is still continuing but to date, Xfinity is “not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” the company said in a statement sent to The Associated Press Tuesday.

Xfinity is also requiring customers to reset their passwords, while strongly recommending two-factor or multifactor authentication.

A filing with Maine's office of the attorney general disclosed that nearly 35.9 million people were affected by this breach. The company declined to confirm a specific number Tuesday, but noted the filing's figure represents user IDs.

Philadelphia-based Comcast has more than 32 million broadband customers, according a recent earnings release.

In addition to Xfinity, Citrix provides software to thousands of companies around the world. The previously-announced vulnerability, dubbed “Citrix Bleed,” has also been linked to hacks targeting the Industrial and Commercial Bank of China's New York arm and a Boeing subsidiary, among others.

Under new rules that went into effect Monday, the Securities Exchange Commission now requires public companies to disclose all cybersecurity breaches that could affect their bottom lines — within four days of determining a breach is material. As of Tuesday, there were no SEC filings from Comcast about the recent data breach and the company did not immediately address it.

Related

Business|Political|Technology|US

TikTok seeks to reassure U.S. employees ahead of Jan. 19 ban deadline

TikTok plans to keep paying U.S. employees even if the Supreme Court does not overturn a law that would force the sale of the short-video app in the U.S

TikTok seeks to reassure U.S. employees ahead of Jan. 19 ban deadline
Asia|Business|Economy|Finance|Political

Japan likely to miss primary budget surplus target for FY2025, sources say

Japan is likely to miss achieving its goal of running a primary budget surplus by the next fiscal year, according to three sources with knowledge of fresh

Japan likely to miss primary budget surplus target for FY2025, sources say
Asia|Business|Economy|Finance|Stock Markets

Oil little changed as falling US stockpiles outweigh soft demand outlook

Oil prices were little changed on Wednesday, after falling the previous day, as a dip in U.S. crude stockpiles and expectations of supply disruptions from sanctions on Russian

Oil little changed as falling US stockpiles outweigh soft demand outlook
Business|Economy|Political|Technology|US

Chip industry groups slam expected rules in private letter to Biden

A half-dozen trade groups from the semiconductor and manufacturing industries sent a private letter to U.S.

Chip industry groups slam expected rules in private letter to Biden
Share This

Popular

Asia|Business|Economy|Finance

BOJ will raise rates if economy, price conditions continue to improve, Ueda says

BOJ will raise rates if economy, price conditions continue to improve, Ueda says
Asia|Business|Economy|Finance|Stock Markets|US

Stock market today: Asian stocks mixed ahead of US inflation data

Stock market today: Asian stocks mixed ahead of US inflation data
Asia|Business|Economy|Political|US

Nippon Steel wants to work with Trump administration on US Steel deal, Mori tells WSJ

Nippon Steel wants to work with Trump administration on US Steel deal, Mori tells WSJ
Business|Economy|Europe|Finance

ECB betting on services prices to get inflation back to target, Lane says

ECB betting on services prices to get inflation back to target, Lane says