Comcast accidentally published 200K “unlisted” phone numbers, with names and addresses, of customers who paid monthly fees to make their numbers unlisted
Comcast made the same mistake once before and had to pay $33 million. — Comcast mistakenly published the names …
Context & Ripple Effects
This is a rerun with a larger cast. In 2015 Comcast settled with California for $33 million after accidentally posting personal details of 75,000 customers online — the same failure mode as today's exposure of 200,000 unlisted numbers, names, and addresses. The intervening record includes [[a:932255|Xfinity web flaws that exposed partial addresses and Social Security numbers of over 26.5 million customers]] in 2018 and a sold-off customer list that forced a mass password reset the same year.
First-order effects
- Roughly 200,000 paying customers lose the exact service they bought: their numbers are now public alongside names and home addresses, directly usable for spam, scams, and harassment.
- Comcast inherits a documented liability trail — its own prior $33M settlement for publishing 75K customers' details gives regulators a ready-made template for what this incident should cost.
Second-order effects
- State attorneys general and the FCC, which has already fined Comcast $2.3M for billing abuses, face pressure to price repeat offenses above the one-time-settlement level rather than treating each leak as isolated.
- Competing carriers can weaponize the pattern: Comcast's privacy record now spans accidental publication, exposed SSNs, and the Citrix breach that hit data on over 35.8 million people, making 'we don't sell your data' claims harder for any cable operator to make credibly.
Third-order effects
- If paid-for privacy keeps failing at the largest US broadband provider, the likely structural response is regulation that treats unlisted-number guarantees as enforceable contracts with per-record penalties, not marketing promises.
- The recurring arc — patchable flaws, breached servers, republished private data — points toward broadband providers being held to data-stewardship standards closer to financial institutions', with compliance costs becoming a permanent line item.
The trend: Customer data at major US broadband providers is being treated less as a protected product feature and more as an operational liability that regulators increasingly price by the incident.