Comcast Discloses Breach Affecting About 36 Million Accounts
Comcast confirmed a breach exposing the personal information of 36 million U.S. Xfinity account holders.
Profit and prosper with the best of Kiplinger's advice on investing, taxes, retirement, personal finance and much more. Delivered daily. Enter your email in the box and click Sign Me Up.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Delivered daily
Kiplinger Today
Profit and prosper with the best of Kiplinger's advice on investing, taxes, retirement, personal finance and much more delivered daily. Smart money moves start here.
Sent five days a week
Kiplinger A Step Ahead
Get practical help to make better financial decisions in your everyday life, from spending to savings on top deals.
Delivered daily
Kiplinger Closing Bell
Get today's biggest financial and investing headlines delivered to your inbox every day the U.S. stock market is open.
Sent twice a week
Kiplinger Adviser Intel
Financial pros across the country share best practices and fresh tactics to preserve and grow your wealth.
Delivered weekly
Kiplinger Tax Tips
Trim your federal and state tax bills with practical tax-planning and tax-cutting strategies.
Sent twice a week
Kiplinger Retirement Tips
Your twice-a-week guide to planning and enjoying a financially secure and richly rewarding retirement
Sent bimonthly.
Kiplinger Adviser Angle
Insights for advisers, wealth managers and other financial professionals.
Sent twice a week
Kiplinger Investing Weekly
Your twice-a-week roundup of promising stocks, funds, companies and industries you should consider, ones you should avoid, and why.
Sent weekly for six weeks
Kiplinger Invest for Retirement
Your step-by-step six-part series on how to invest for retirement, from devising a successful strategy to exactly which investments to choose.
Comcast has confirmed a security breach affecting 36 million U.S. Xfinity accounts, according to media reports.
Comcast said that hackers exploited a vulnerability in third-party software provider, Citrix, which it uses for remote network access, according to a December 19 Wall Street Journal (WSJ) report.
The breach occurred between October 16 and 19, exposing usernames, hashed passwords, names, contact information, birth dates, the last four digits of users’ social security numbers and secret questions and answers, WSJ said.
From just $107.88 $24.99 for Kiplinger Personal Finance
Become a smarter, better informed investor. Subscribe from just $107.88 $24.99, plus get up to 4 Special Issues
Sign up for Kiplinger’s Free Newsletters
Profit and prosper with the best of expert advice on investing, taxes, retirement, personal finance and more - straight to your e-mail.
Profit and prosper with the best of expert advice - straight to your e-mail.
The company joins a long list of well-known brands hit by cyber attacks this year, including genetic testing company 23andMe, which earlier this month disclosed a data breach affecting 6.9 million users.
On October 10, the week before Comcast’s breach, Citrix published an advisory on its website about two vulnerabilities in its systems. According to an October 27 report from cybersecurity firm Rapid7, the two vulnerabilities allow “an attacker to read large amounts of memory after the end of a buffer,” that in turn would allow a bad actor to “impersonate another authenticated user.”
Citrix released a software update to fix the vulnerability on October 23. It also noted that it received reports of session hijacking and targeted attacks exploiting the vulnerability.
“We are not aware of any customer data being leaked anywhere, nor of any attacks on our customers,” a Comcast spokesperson told the WSJ in the report. He added that the company is requiring customers to reset their passwords and recommends enabling multi-factor authentication.
How to secure your Xfinity account
If you're an Xfinity customer, you’ll want to follow the company’s guidance and immediately change your password. Experts recommend choosing a secure, easy-to-remember password, such as a nonsensical combinations of symbols, numbers and upper-and-lower-case numbers.
Experts also encourage people to strongly consider enabling multi-factor authentication, just as Comcast has recommended for its customers.
To do this for your Xfinity account, download the company's app, which the company says is available for download on Apple and Android phones. Then follow these steps. You will then be able to approve or deny log-in attempts with a yes/no button push, facial recognition, one-touch fingerprint ID, traditional text message or email codes, or a code generator.
Related Content
Profit and prosper with the best of Kiplinger's advice on investing, taxes, retirement, personal finance and much more. Delivered daily. Enter your email in the box and click Sign Me Up.

Joey Solitro is a freelance financial journalist at Kiplinger with more than a decade of experience. A longtime equity analyst, Joey has covered a range of industries for media outlets including The Motley Fool, Seeking Alpha, Market Realist, and TipRanks. Joey holds a bachelor's degree in business administration.
-
Stocks Sink With Alphabet, Bitcoin: Stock Market TodayA dismal round of jobs data did little to lift sentiment on Thursday.
-
Betting on Super Bowl 2026? New IRS Tax Changes Could Cost YouTaxable Income When Super Bowl LX hype fades, some fans may be surprised to learn that sports betting tax rules have shifted.
-
How Much It Costs to Host a Super Bowl Party in 2026Hosting a Super Bowl party in 2026 could cost you. Here's a breakdown of food, drink and entertainment costs — plus ways to save.
-
Texas Sales Tax-Free Weekend 2025Tax Holiday Here's what you needed to know about the Texas sales tax holiday.
-
Florida Back-to-School Tax-Free Holiday 2025Sales Taxes The new tax-free holiday in Florida brought month-long savings on computers, clothing and other school supplies.
-
Visa, Mastercard's Swipe Fee Settlement Might Save You Money, For NowThe limited-time agreement directly benefits merchants, which can potentially pass savings on to consumers.
-
New List Out On Medicare Part B Drugs Eligible for RebatesSome Medicare beneficiaries may pay lower coinsurance rates from April 1 to June 30 for the drugs, HHS says.
-
Use An iPhone? You May Be Hearing From A Class-Action Lawsuit GroupA handful of suits against the iPhone maker seek to crack down on everything from app store purchases to messaging.
-
Capital One/Discover: What's In Their Wallet For You?Push back on Capital One's planned merger with Discover is growing with one group of consumer advocates calling for a public hearing.
-
Lawmakers: Nix Social Security Offsets For Seniors In Student Loan DefaultOffsetting Social Security benefits to pay for defaulted student loans can be devastating for some beneficiaries, lawmakers say.
-
Stellantis Recalls 285K Vehicles Over Airbag ProblemsDefective airbag inflators on certain Chrysler and Dodge vehicles could rupture and cause injury or death, NHTSA says.