Comcast Corp.'s Xfinity disclosed a data breach in a notice published on Xfinity's website.
The "data security incident" caused the theft of customer passwords and usernames. In contrast, for some users, the theft might have resulted in the "possible" acquirement of additional personal information such as "names, contact information, last four digits of social security numbers, dates of birth and secret questions and answers," as stated in the notice.
The breach occurred due to a "vulnerability" in software used by Xfinity and other companies. This vulnerability was reported by Citrix Systems Inc. on October 10, 2023, and was subsequently patched by Xfinity. However, unauthorized access to internal systems occurred between October 16 and October 19, 2023, resulting in the theft of information.