Xfinity
ent_c8b492b29f13ad25badf17d5
Disclosures
2
State AG · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Xfinity
- Normalized
- xfinity— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- 💎Delaware State AGas victim2024-01-26
Xfinity (Comcast Cable Communications LLC) notified Delaware residents of a data breach involving unauthorized access to internal systems via a Citrix software vulnerability between October 16-19, 2023. The incident exposed names, Social Security numbers, and driver's license numbers. Xfinity patched the vulnerability, notified law enforcement, and offered 24 months of credit monitoring and identity restoration services through IDX.
- 💎Delaware State AGas victim2023-12-18
Xfinity (Comcast Cable) disclosed a data security incident involving unauthorized access to internal systems via a Citrix software vulnerability between October 16-19, 2023. The breach exposed usernames, hashed passwords, and for some customers, names, contact info, last four SSN digits, and dates of birth. Xfinity patched systems, reset passwords, and notified law enforcement. This notice covers Delaware, New York, and North Carolina residents.