• Video
  • Shop
  • Culture
  • Family
  • Wellness
  • Food
  • Living
  • Style
  • Travel
  • News
  • Book Club
  • Newsletter
  • Privacy Policy
  • Your US State Privacy Rights
  • Children's Online Privacy Policy
  • Interest-Based Ads
  • Terms of Use
  • Do Not Sell My Info
  • Contact Us
  • © 2026 ABC News
  • News

Xfinity hack could compromise user information from 36 million customers, state AG says

1:10
Headlines from ABC News Live
David Paul Morris/Bloomberg via Getty Images, FILE
ByLuke Barr
December 20, 2023, 6:54 PM

Hackers compromised a vulnerability in a third-party vendor that serviced Xfinity, which lead to some customer information being stolen, a state attorney general's report said.

Nearly 36 million people could be impacted by the hack, according to a filing from the Maine Attorney General's office.

On Oct. 10, Citrix announced there was a vulnerability in its software, the filing said. Xfinity patched the system initially, but on Oct. 23, Citrix announced it issued "additional mitigation guidance" to further address the vulnerability.

"However, we subsequently discovered that prior to mitigation, between October 16 and October 19, 2023, there was unauthorized access to some of our internal systems that we concluded was a result of this vulnerability," Xfinity said, according to the filing. "We notified federal law enforcement and conducted an investigation into the nature and scope of the incident. On November 16, 2023, it was determined that information was likely acquired."

In this Sept. 26, 2023 file photo, a Comcast Xfinity store is shown in Daly City, Calif.
David Paul Morris/Bloomberg via Getty Images, FILE

Xfinity concluded on Dec. 6 that usernames and passwords for some customers were stolen along with names, contact information, last four digits of social security numbers, dates of birth and/or secret questions.

The company says it is still taking a complete stock of what was stolen.

Related Articles

MORE: Mortgage giant Mr. Cooper hit with cyberattack possibly affecting more than 14 million customers

Xfinity is recommending users proactively reset their passwords and said, "and we can't emphasize enough how seriously we are taking this matter."

"Customers trust Xfinity to protect their information, and the company takes this responsibility seriously. Xfinity remains committed to continued investment in technology, protocols and experts dedicated to helping to protect its customers," Xfinity said in a press release.

Comcast, Xfinity's parent company, said it is not aware of any customers' data being leaked anywhere. It recommended its customers reset their passwords and enable two-factor authentication.

"We take the responsibility to protect our customers very seriously and have our cybersecurity team monitoring 24x7," Comcast wrote in a statement.

Citrix said it couldn't comment directly on the Comcast data breach.

Editor's note: This story has been updated to statements from Comcast and Citrix. It also clarifies the Citrix mitigation guidance offered in October.

Up Next in News—

Empty Waymo vehicles swarm Atlanta cul-de-sac

May 15, 2026

Homeowner speaks out after plane crashes into house, causing fire

May 15, 2026

GM CEO Mary Barra talks economy, AI and more

May 15, 2026

Officer nearly shoots student playing with water gun in a senior game

May 15, 2026

Shop GMA Favorites

ABC will receive a commission for purchases made through these links.

Sponsored Content by Taboola

The latest lifestyle and entertainment news and inspiration for how to live your best life - all from Good Morning America.
  • Contests
  • Terms of Use
  • Privacy Policy
  • Do Not Sell My Info
  • Children’s Online Privacy Policy
  • Advertise with us
  • Your US State Privacy Rights
  • Interest-Based Ads
  • About Nielsen Measurement
  • Press
  • Feedback
  • Shop FAQs
  • ABC News
  • ABC
  • All Videos
  • All Topics
  • Sitemap

© 2026 ABC News
  • Privacy Policy— 
  • Your US State Privacy Rights— 
  • Children's Online Privacy Policy— 
  • Interest-Based Ads— 
  • Terms of Use— 
  • Do Not Sell My Info— 
  • Contact Us— 

© 2026 ABC News