Data leak
Comcast/Xfinity Customer Data Breach via FBCS Third-Party (FCC Fine)
Primary Source βIncident Details
Financial Business and Consumer Solutions (FBCS), a third-party debt collection agency used by Comcast, was hit by ransomware in February 2024. As a result, data on approximately 273,703β275,000 Comcast broadband subscribers was exposed. Comcast was notified by FBCS in July 2024 and began customer notifications in October 2024. The FCC investigated Comcast for its breach notification handling and delayed response; Comcast agreed to pay a $1.5 million fine to settle the FCC investigation. Exposed data included names, addresses, SSNs, and account information. Note: separate from the Comcast Xfinity CitrixBleed breach in late 2023 (which exposed 35.8 million customers). This is a distinct 2024 third-party vendor exposure event affecting a much smaller subset of customers.
Technical Details
- Initial Attack Vector
- Third-party vendor breach: Financial Business and Consumer Solutions (FBCS), a debt collection agency handling Comcast customer accounts, was compromised in a ransomware attack February 14β26, 2024
Timeline
- 2024-02-14 Breach occurred
- 2024-10-01 Publicly disclosed
- 2024-10-01 Customers notified