HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Xfinity
bd_5bfeb65433187961 · schema v1 · pii pii-v1
Full breach record for Xfinity →Xfinity (Comcast Cable Communications LLC) notified Delaware residents of a data breach involving unauthorized access to internal systems via a Citrix software vulnerability between October 16-19, 2023. The incident exposed names, Social Security numbers, and driver's license numbers. Xfinity patched the vulnerability, notified law enforcement, and offered 24 months of credit monitoring and identity restoration services through IDX.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5355437d076882a9Delaware State AGfiled 2023-12-18(39d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/01/SSN_DL-Notice-New_static-proof-r1.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 26, 2024
- Raw hash
- 54e9f2bb0334ab6ea6b3b660a3b6018daf9386fbc03112de8f7b6b67167689e1
Reporting entity
- Name
- Xfinitynorm: xfinity
Victim entity
- Name
- Xfinitynorm: xfinity
Incident
- Discovered
- Oct 19, 2023
- Materiality determined
- Nov 16, 2023
- Notification sent
- Jan 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
- Third party
- via Citrix
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(99 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.