Comcast's Xfinity says hackers breached one of its Citrix servers in October 2023, two weeks after Citrix issued a patch, and stole data on 35,879,455 people
what we know Laura French / SC Media : 35 million Xfinity customers have data leaked in breach tied to Citrix Bleed bug Helga Labus / Help Net Security : Citrix Bleed leveraged to steal data of 35+ million Comcast Xfinity customers Mastodon: BrianKrebs / @briankrebs@infosec.exchange : ICYMI, Comcast/Xfininty disclosed yesterday that a recent Citrix vulnerability was used to steal data on 35 million people, including usernames, passwords, contact info and partial SSNs. — https://www.bleepingcomputer.com/ ... Comcast was just one of hundreds of companies rinsed by data ransom groups that pounced on the Citrix bug. @SteveD3@infosec.exchange : The likely compromise of password reset Q&As is concerning. In many cases, the user and their accounts in an unwinnable game of guess the answer, where the answer can be a bit of personal trivia, or an easily guessed phrase or word. — https://technicaloutcast.com/ ... X: Brett Callow / @brettcallow : #Comcast has disclosed a #CitrixBleed-related data breach which affected 35 million #Xfinity customers. The impacted info included names, contact information, last four digits of social security numbers, dates of birth and secret questions and answers. https://apps.web.maine.gov/... [image] Dave Kennedy / @hackingdave : Big one, and many more coming that are discovering the Citrix bleed vuln used in their environment Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Hackers stole the personal data of 36 million Comcast customers, the company says. Data includes: customer names, usernames, dates of birth, hashed passwords, and some partial Social Security numbers were exposed. https://techcrunch.com/... @vxunderground : Comcast has reported a security breach impacting 35,879,455 Xfinity customers. It is reported the breach was discovered December 6th, 2023 with a suspected initial breach date of mid-October, 2023. Information via @BrettCallow [image]
Context & Ripple Effects
The disclosure lands against a history of Xfinity customer-data exposure: a 2018 Xfinity flaw exposed partial addresses and Social Security numbers and Comcast later reset nearly 200,000 passwords after a customer list surfaced for sale. The latest incident is materially larger and ties the exposure to a shared enterprise access product rather than an Xfinity site flaw.
It also extends Citrix's own security record: Citrix disclosed a months-long network intrusion in 2020. Here, the reported gap between the Citrix patch and Comcast's October breach makes patch deployment—not just vulnerability disclosure—the operational issue.
First-order effects
- Xfinity must manage a breach affecting 35,879,455 people whose stolen information reportedly includes usernames, passwords, contact details, and partial Social Security numbers.
- The incident shows attackers could exploit Citrix Bleed against Comcast's Citrix environment after a patch was available, putting its exposure-management and customer-account protections under immediate pressure.
Second-order effects
- Affected customers face elevated phishing and account-takeover risk, particularly where exposed passwords were reused; Comcast may need to absorb the support and remediation burden that follows.
- Organizations operating Citrix infrastructure have a concrete incentive to verify whether the patch was deployed and whether access systems show signs of compromise, rather than treating patch publication as the end of response.
Third-order effects
- If similar cases persist, enterprise security programs will be judged increasingly on the speed and verification of patch rollout across externally reachable systems, not solely on whether vendors released fixes.
- The event reinforces how a vulnerability in widely deployed access software can create correlated exposure across otherwise unrelated companies, concentrating cyber risk in common infrastructure layers.
The trend: Citrix Bleed is part of a broader trend in which attackers turn delayed remediation of shared enterprise access infrastructure into large-scale customer-data incidents.