HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)CREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENTAUTHENTICATIONMediumContained
COMCAST CABLE COMMUNICATIONS, LLC
bd_9483a5f6ebb2a493 · schema v1 · pii pii-v1
Full breach record for COMCAST CABLE COMMUNICATIONS, LLC →Comcast Cable Communications LLC disclosed unauthorized access to internal systems between Oct 16-19, 2023, resulting from a vulnerability in Citrix software. The incident involved usernames, hashed passwords, and for some customers, names, contact info, last four digits of SSN, DOB, and secret questions. Systems were patched, law enforcement notified, and customers prompted to reset passwords and enable MFA.
California clockDiscovered Oct 23, 2023 → Notified Dec 6, 202344d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_3823dc42ff458d5aVermont State AGfiled 2023-12-18Verified
- bd_cf68c61c04a06b88Washington State AGfiled 2023-12-18Candidate
- bd_d0e6f01e879a4506Maine State AGfiled 2023-12-18Verified
- bd_e1e3e7f42684ebc9Oregon State AGfiled 2023-12-18Verified
Show 2 more filings ↓Show fewer ↑up to 39d gap
- bd_62f3f759d84e3a66Indiana State AGfiled 2024-01-26(39d gap)Verified
- bd_7ffaf039f7f863fdMaine State AGfiled 2024-01-26(39d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578091
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 18, 2023
- Raw hash
- c6592922c1d6c2a7b4678e292fccec1754adc09d5bce8ab4719fe7af2e667dab
Reporting entity
- Name
- COMCAST CABLE COMMUNICATIONS, LLCnorm: comcast cable communications
Victim entity
- Name
- COMCAST CABLE COMMUNICATIONS, LLCnorm: comcast cable communications
Incident
- Discovered
- Oct 23, 2023
- Materiality determined
- —
- Notification sent
- Dec 6, 2023
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASICIDENTITY_GOVERNMENTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
- Third party
- via Citrix
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 44d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 23, 2023→ Notified: Dec 6, 202344d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.