$117.5M Comcast data breach settlement: Who qualifies and how to file a claim

The 2023 data breach exposed usernames, hashed passwords, and in some cases the last four digits of Social Security numbers, contact information and security answers.

WASHINGTON — Xfinity customers may be eligible for cash and identity theft monitoring after Comcast agreed to pay $117.5 million to settle a class action lawsuit stemming from a 2023 cyberattack that exposed the personal information of millions of Xfinity customers, according to court documents.

The proposed settlement, pending approval in the U.S. District Court for the Eastern District of Pennsylvania, will resolve claims that Comcast failed to adequately protect customer data after hackers exploited a vulnerability in Citrix software between October 16 and October 19, 2023. The company disclosed the breach in December 2023.

The attack affected an estimated 35.8 million customers – more than the company’s entire broadband customer base at the time – exposing usernames, hashed passwords, and in some cases the last four digits of Social Security numbers, contact information and security questions and answers.

Comcast denies any wrongdoing or violations of law.

Comcast Settlement: Who is Eligible for Payment?

Customers who received notification of the breach from Comcast are automatically included in the settlement class.

Eligible customers can file a claim to be reimbursed for out-of-pocket documented losses – such as costs related to identity theft, credit monitoring services or a credit freeze that occurred after October 16, 2023 – up to a limit of $10,000. Customers who have spent time dealing with fraud or taking preventive measures can also claim up to five hours of lost time at a rate of $30 per hour.

Those who do not have documented losses can opt for an alternative cash payment of about $50, although that amount may be adjusted up or down depending on how many claims are filed.

All members of the settlement class are automatically eligible to enroll in three years of identity protection services, including credit monitoring, dark web monitoring, up to $1 million in identity theft insurance, and access to fraud experts.

Key Deadlines and How to File a Claim

The last date to file claims is August 14.

Claims may be submitted online at www.comcastbreachsettlement.com or mailed to the settlement administrator, Kroll Settlement Administration LLC. Customers will need to provide a unique Class Member ID which was sent via email or can be viewed online.

The court is scheduled to hold a final approval hearing on July 7.

Customers who do nothing will remain part of the settlement class, give up their right to sue over the breach, and will not receive a cash payment – ​​but they will still be able to enroll in identity protection services after the settlement is finalized.

For more information or to file a claim, visit the settlement website or call (833) 319-2401.



<a href=

Leave a Comment