Xfinity recently reported a significant data breach incident impacting 36 million Xfinity customers nationwide. USA Today and CBS News confirm the breach was caused by the exploitation of a critical security vulnerability that has been under mass-exploitation by hackers since late August 2023. Citrix had issued patches for this vulnerability in early October, but technology publications like ArsTechnica suggest that many organizations, including Xfinity, did not implement these patches in time.
According to MSN, between October 16 and October 19, 2023, hackers gained unauthorized access to Xfinity’s internal systems. The company did not detect this malicious activity until October 25. By November 16, Xfinity confirmed that customer data was likely acquired by the hackers. In December, they announced that the breached data included customer usernames and hashed passwords. For some customers, additional data such as names, contact information, dates of birth, the last four digits of Social Security numbers, and secret questions and answers were also compromised. While the company asserts that there is no evidence of the leaked data being used maliciously or any ransom demands being made, the incident raises questions about Xfinity’s cybersecurity practices, particularly regarding the timely patching of known vulnerabilities and the measures needed to prevent similar breaches in the future. The company may release more information about the breach.
Labaton is investigating the pursuit of private arbitration claims against Xfinity on behalf of Xfinity members who were notified that their personal and account information were exposed as a result of this breach. Successful claims could be entitled to compensation of up to $750 under California privacy laws.