HackingVulnerability ExploitStolen CredentialsData ExfiltratedDelayed DiscoveryCREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
COMCAST CABLE COMMUNICATIONS, LLC
bd_3823dc42ff458d5a · schema v1 · pii pii-v1
Full breach record for COMCAST CABLE COMMUNICATIONS, LLC →Comcast Cable Communications (Xfinity) notified consumers of a data security incident where unauthorized access occurred between Oct 16-19, 2023, exploiting a Citrix vulnerability. Information acquired included usernames, hashed passwords, names, contact info, last 4 digits of SSNs, and DOBs. Comcast patched systems, notified law enforcement, and required password resets.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_9483a5f6ebb2a493California State AGfiled 2023-12-18Verified
- bd_cf68c61c04a06b88Washington State AGfiled 2023-12-18Candidate
- bd_d0e6f01e879a4506Maine State AGfiled 2023-12-18Verified
- bd_e1e3e7f42684ebc9Oregon State AGfiled 2023-12-18Verified
Show 2 more filings ↓Show fewer ↑up to 39d gap
- bd_62f3f759d84e3a66Indiana State AGfiled 2024-01-26(39d gap)Verified
- bd_7ffaf039f7f863fdMaine State AGfiled 2024-01-26(39d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-18-comcast-cable-communications-xfinity-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 18, 2023
- Raw hash
- 7ac50511fc059d68006fe3276bea4fd4ecf8115a2320e891a807cb4fd004f670
Reporting entity
- Name
- COMCAST CABLE COMMUNICATIONS, LLCnorm: comcast cable communications
Victim entity
- Name
- COMCAST CABLE COMMUNICATIONS, LLCnorm: comcast cable communications
Incident
- Discovered
- Oct 16, 2023
- Materiality determined
- Nov 16, 2023
- Notification sent
- Dec 18, 2023
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.