Xfinity disclosed breach exposing personal data of 35.8 million customers via Citrix Bleed vulnerability
Dec 18, 2023On December 18, 2023 Comcast's Xfinity broadband unit disclosed a data breach affecting approximately 35.8 million customers, in which attackers exploited the CVE-2023-4966 'Citrix Bleed' vulnerability between October 16-19, 2023. Exposed data included usernames, hashed passwords, partial Social Security numbers, dates of birth, contact information and secret questions/answers. Xfinity disclosed only after a 2-month delay, exposing affected customers to credential-stuffing risk during the gap.