Skip to main content
  1. Home
  2. Computing
  3. News

Use Comcast for internet? Your personal data may have been hacked

Add as a preferred source on Google
A building with the Xfinity logo on it.
Comcast

Comcast, alongside several other big corporations, has recently suffered a devastating data breach. According to reports, it’s possible that hackers got their hands on the data of up to 36 million Comcast Xfinity customers, meaning the company’s cable television and internet department. Although the company is pretty tight-lipped about it, the data breach occurred over two months ago. Here’s what we know and what you should do to protect yourself.

The hackers were able to access those masses of customer information through a vulnerability known as “CitrixBleed.” It’s found in Citrix networking devices that Comcast and other huge corporations use. The exploit was initially discovered in August and appears to have been used in cyberattacks on not just Comcast but also many other companies, including Boeing.

Recommended Videos

Since the vulnerability was first spotted in August, it took until early October for Citrix to release a patch. However, it appears that not every company was able to get the critical updates in time, including Comcast. The telecom giant admitted that the CitrixBleed vulnerability allowed hackers to access its systems, which means customer data, between October 16 and 19. It took another week for Comcast to detect this attack.

The timeline stretches all the way until this month. On November 16, Xfinity confirmed that “information was likely acquired,” but it didn’t specify what type of information. This month, Comcast revealed that customer data was stolen, including usernames and hashed passwords, and this appears to affect most — if not all — of the 36 million accounts, which translates to just about all the customers Xfinity has.

The good news is that the hashed passwords are supposed to be hard to crack, but depending on the algorithm used to protect them, it’s not impossible for the hackers to get around those defenses.

The worst part of it all is that Comcast admits that the hackers may have gotten their hands on much more sensitive data for an “unspecified number of customers,” says TechCrunch. This data includes names, dates of birth, contact information, secret questions and answers, and even the last four digits of Social Security numbers. Unfortunately, Comcast doesn’t specify how many customers are affected by this — far more severe — data breach.

It’s unclear whether the hackers are asking for ransom right now, although Comcast told TechCrunch that it’s not aware of the data being leaked anywhere or used for malicious purposes. It’s possible that the hackers may attempt to sell the data on the dark web or request ransom from Comcast.

What can you do as a Comcast customer? Your best bet is to change your password, and if you’ve been using that same password elsewhere, make sure to change it across the board (and use different passwords for every service going forward). Using two-factor authentication is also a good way to protect yourself at a time when cyberattacks and massive data breaches are such a common occurrence, with companies like Western Digital, Microsoft, and 1Password all being affected this year.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
Researchers discover AI attack that rewrites an assistant's long-term memory
Chatbot on a smartphone.

Large language models are getting better at remembering us. Whether it's your preferred writing style, recurring tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more personal and useful. But according to new research, that same feature could become one of AI's biggest security vulnerabilities.

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, capable of secretly planting false memories inside AI agents. Rather than stealing information outright, the attack manipulates what an AI remembers, potentially causing it to make dangerous decisions long after the original attack has taken place.

Read more
This experiment shows how easy it is to poison an open-weight AI model for under $100
This research raises new doubts about trusting open weight AI models.
Computer, Electronics, Laptop

Open-weight AI models have been having a moment lately. Just this month, Moonshot's massive Kimi K3 model landed close behind Claude Fable 5 and GPT 5.6 Sol in several benchmarks, all while remaining fully open-weight and downloadable by anyone.

However, Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, managed to poison an open-weight model and proved how easily that openness can be turned against you (via The Register).

Read more
Asus’ powerful new gaming laptop with a 240Hz Mini LED display makes its global debut
The 2026 ROG Strix G18 pairs up to RTX 5080 graphics with an Intel Core Ultra 9 290HX Plus CPU
ROG Strix G18 (2026) laptop

Asus has started rolling out the 2026 ROG Strix G18 globally, and the easiest way to describe it is as a slightly toned-down version of the ridiculous ROG Strix Scar 18. It keeps the same 24-core Intel Core Ultra 9 290HX Plus processor but tops out at an Nvidia GeForce RTX 5080 Laptop GPU instead of the Scar’s RTX 5090. (via Notebookcheck)

The Mini LED model gets the best balance

Read more