Security

Comcast says hackers stole data of close to 36 million Xfinity customers

Comment

Xfinity storefront
Image Credits: Comcast

Comcast has confirmed that hackers exploiting a critical-rated security vulnerability accessed the sensitive information of almost 36 million Xfinity customers.

This vulnerability, known as “CitrixBleed,” is found in Citrix networking devices often used by big corporations and has been under mass-exploitation by hackers since late August. Citrix made patches available in early October, but many organizations did not patch in time. Hackers have used the CitrixBleed vulnerability to hack into big-name victims, including aerospace giant Boeing, the Industrial and Commercial Bank of China and international law firm Allen & Overy.

Xfinity, Comcast’s cable television and internet division, became the latest CitrixBleed victim, the company confirmed in a notice to customers on Monday.

The U.S. telecom giant said that hackers exploiting the CitrixBleed vulnerability had access to its internal systems between October 16 and October 19, but that the company did not detect the “malicious activity” until October 25.

By November 16, Xfinity determined that “information was likely acquired” by the hackers, and in December, the company concluded that this included customer data, including usernames and “hashed” passwords, which are scrambled and stored in a way that makes them unreadable to humans. It’s not immediately clear how the passwords were scrambled or using which algorithm, as some weaker hashing algorithms can be cracked.

The company says for an unspecified number of customers, hackers may have also accessed names, contact information, dates of birth, the last four digits of Social Security numbers and their secret questions and answers.

Comcast notes that “our data analysis is continuing, and we will provide additional notices as appropriate,” suggesting additional types of data may also have been accessed.

The notice doesn’t say how many Xfinity customers have been impacted, and Comcast spokesperson Joel Shadle declined to say when asked by TechCrunch. In a filing with Maine’s attorney general, Comcast confirmed that almost 35.8 million customers are affected by the breach. Comcast’s latest earnings report shows the company has more than 32 million broadband customers, suggesting this breach has impacted most, if not all Xfinity customers.

It’s not yet known whether Xfinity received a ransom demand, how the incident has impacted the company’s operators or whether the incident has been filed with the U.S. Securities and Exchange Commission, as required by the regulator’s new data breach reporting rules. Comcast’s spokesperson would not say.

“We are not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” said Shadle in an email to TechCrunch.

Xfinity says it is requiring that customers reset their passwords and recommends the use of two-factor or multi-factor authentication — which the company doesn’t require by default — for all customer accounts.

Updated with additional comment from Comcast.

Read more on TechCrunch:

Tech gifts you shouldn’t buy your family and friends for the holidays

More TechCrunch

SpaceX President Gwynne Shotwell made a public plea to one of Brazil’s top judicial figures on Thursday, asking him to “please stop harassing Starlink” amid the ongoing battle in the…

‘Stop harassing Starlink,’ SpaceX president tells Brazilian judge

OSOM always had a difficult road, with plans to launch a privacy-focused handset.

Osom is shutting down on Friday, as it had ‘no customers for a mobile phone’

Salesforce has acquired Own Company, a New Jersey-based provider of data management and protection solutions, for $1.9 billion in cash. Own is Salesforce’s biggest deal since buying Slack for $27.7…

Salesforce acquires data management firm Own for $1.9B in cash

The U.S. government indictment demonstrated deep knowledge of the Russian spies’ activities, including their real-world meetings at a cafe in Moscow.

US charges five Russian military hackers with targeting Ukraine’s government with destructive malware

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Short week,…

Lyft restructures its micromobility business and Volkswagen brings ChatGPT to US vehicles 

The advancement of generative AI tools has created a new problem for the internet: the proliferation of synthetic nude images resembling real people. On Thursday, Microsoft took a major step…

Microsoft gives deepfake porn victims a tool to scrub images from Bing search

The new business-to-business division is a bet on what co-founder and CEO Thomas von der Ohe thinks is the future of mobility.

Driverless car-sharing startup Vay steers toward B2B services

Drip Capital has raised $113 million in a combination of $23 million in equity and $90 million in debt to provide credit to more small businesses in India and the…

Drip Capital, a fintech that provides working capital to SMBs, picks up $113M

Google said the feature could be used for more than just photo retrieval alone; users would also be able to ask questions to get helpful answers.

Google’s AI-powered Ask Photos feature begins US rollout

The stealthily operating startup thinks it can narrow the gap by helping miners extract more copper from their mines.

Endolith is using ‘Olympic-caliber’ copper microbes to address the copper shortage

Featured Article

A comprehensive list of 2024 tech layoffs

A complete list of all the known layoffs in tech, from Big Tech to startups, broken down by month throughout 2024.

A comprehensive list of 2024 tech layoffs

As with many open source startups, All Hands AI expects to monetize its service by offering paid, closed-source enterprise features.

All Hands AI raises $5M to build open source agents for developers

Mintlify offers a collection of documentation-authoring tools, including tools that can auto-generate docs from codebases.

Mintlify is building a next-gen platform for writing software docs

Europe doesn’t have many large language model (LLM) makers but one of these rare AI beasts — Germany’s Aleph Alpha — appears to be preparing to rule itself out of…

German LLM maker Aleph Alpha pivots to AI support

Featured Article

The AI industry is obsessed with Chatbot Arena, but it might not be the best benchmark

LMSYS’ Chatbot Arena is perhaps the most popular AI benchmark today — and an industry obsession. But it’s far from a perfect measure.

The AI industry is obsessed with Chatbot Arena, but it might not be the best benchmark

Every automaker is aiming to build and sell the so-called software-defined vehicle. Rivian may have actually done it, but getting there wasn’t easy. Just ask Rivian’s chief of software Wassym…

Rivian’s chief software designer is coming to TechCrunch Disrupt 2024

Google announced Thursday that it expanded its generative AI-powered virtual try-on tool to support dresses, allowing users to virtually wear thousands of dresses from hundreds of brands, including Boden, Maje,…

Google expands AI-powered virtual try-on tool to include dresses

Until six years ago, many e-commerce and SaaS businesses could have avoided paying sales tax to states where they had customers, but no physical presence. But as online shopping grew,…

Zamp targets growing demand for sales tax solutions

TechCrunch Disrupt 2024, which takes place from October 28-30 at Moscone West in San Francisco, is rapidly approaching. Today we’re thrilled to announce the 200 startups selected to participate in…

Announcing the Startup Battlefield 200 at TechCrunch Disrupt 2024

YouTube is going to limit teens’ exposure to videos that promote and idealize a certain fitness level or physical appearance, the company announced on Thursday. The safeguard first rolled out…

YouTube to limit teens’ exposure to videos about fitness and weight across global markets

Also of note, YouTube is in the early stages of coming up with a solution to address the use of its content to train AI models.

YouTube is developing AI detection tools for music and faces, plus creator controls for AI training

We’re not very close to any specifics on how, exactly, AI regulations will be implemented and ensured, but today a swathe of countries including the U.S., the U.K. and the…

US, UK and EU sign on to the Council of Europe’s high-level AI safety treaty

With a fresh $35M in the bank, French cleantech startup Calyxia has profitability within sight. But it’s just getting started.

French clean tech startup Calyxia nets $35M to tackle microplastics pollution

Hiring platform ZipRecruiter is launching a new tool, called ZipIntro, to let employers schedule introductory calls with potential candidates at a set time. The tool will also help recruiters suggest…

ZipRecruiter’s new tool will quickly match and schedule an intro call with potential candidates

This week at IFA in Berlin, DJI is once again going small with the new Neo. Like the Spark before it, the drone’s ability to land in the palm of…

DJI takes another crack at palm-sized drones, and this one is $199

Brittany Ennix launched Portex, a company that allows SMBs to connect with freight partners and manage shipments and operations in one place.

Portex founder Brittany Ennix learned the importance of supply chains from Uber and Flexport

Verizon’s big interest in Frontier is its fiber business and the fact that it extends to places that Verizon does not currently cover as well.

Verizon bets on fiber’s staying power as it acquires Frontier for $20B

For financial institutions, complying with regulations is becoming a costlier proposition. According to a recent poll, 76% of financial services firms increased their compliance expenditure from 2022 to 2023, with…

Sedric monitors the communications of employees at financial institutions to ensure compliance

Over a year ago, former Session M exec Eben Pingree received the news that his mother was diagnosed with Alzheimer’s. Two days later, his father-in-law was given the same diagnosis. …

Kinsome aims to bridge the generation gap with its new app for kids and grandparents

European regulators are pushing hard for greener energy. The REPowerEU plan calls for 10 million additional heat pumps to be added by 2027, and solar panels are also on the…

Reonic raises €13 million to help small installers of green tech like heat pumps and solar panels