Data breach

©Just_Super via Canva.com

Comcast’s Xfinity Faces a Massive Data Breach

December 20, 2023

Comcast’s Xfinity has been hit by a major data breach. The telecom giant recently reported a “data security incident” affecting its users, with unauthorized access to its systems between Oct. 16 and Oct. 19, 2023. The stolen data included customer usernames, encrypted passwords, contact details, fragments of social security numbers, and more.

“We are not aware of any customer data being leaked anywhere, nor of any attacks on our customers. We take the responsibility to protect our customers very seriously and have our cybersecurity team monitoring 24×7.”

Joel Shadle , Xfinity spokesperson, via The Verge

According to BleepingComputer, the breach notice released in Maine revealed that a staggering 35,879,455 people globally were impacted. That’s over 50,000 people in the state of Maine alone.

The breach was traced back to a security flaw in the cloud company Citrix’s software, which is widely used by Xfinity and various other corporations. Citrix had issued an advisory regarding the vulnerability, now called “Citrix Bleed,” on Oct. 10, urging companies to implement a patch as swiftly as possible. Despite the alert, it seems Xfinity’s measures were a step too late.

Xfinity did apply the recommended patch, but subsequent investigations revealed suspicious activities on its networks. It was deduced that these irregularities were the direct result of the “Citrix Bleed.” It wasn’t until Oct. 18 that security research firm, Mandiant, announced that the vulnerability was under “active exploitation,” alerting the community about the threat.

Stolen data in this breach encompassed usernames and hashed passwords and, for some unfortunate customers, also extended to their names, contact details, the last four digits of their social security numbers, birth dates, and even secret question-answer pairs.

Following these security breach revelations, Xfinity is taking action to protect its customers. The company has reported the matter to federal law enforcement and continuing its analysis of the breached data. When users next log into their accounts, Xfinity will ask them to change their passwords. The company is also promoting the use of two-factor authentication to add an extra layer of security. Details of Xfinity’s announcement can be found on its website.

Recent News

Google’s Antitrust Trial Teeters On

Google’s landmark antitrust case against the Justice Department has reached its final stage, sparking concern across Silicon Valley. Prosecutors argue that Google’s dominance in online search and search advertising markets is illegal, while Google maintains its superiority. The outcome, to be decided by US District Judge Amit Mehta, could have significant implications not only for Google but also for other tech giants like Apple, Amazon, and Meta.

Apple’s Vision Pro Headset Dominates Enterprise Market

Apple’s Vision Pro headset, a mixed-reality spatial computing device, has found its way into the arsenals of more than half of the Fortune 100 companies, with over 50% investing in at least one unit. This revelation came during Apple’s first quarter 2024 earnings call, where CEO Tim Cook highlighted the enthusiastic reception of their products within the corporate sector.