Millions of current and former Xfinity customers can claim a flat $50 cash payment, with no receipts and no documentation, from a $117.5 million settlement over a 2023 data breach, but the window closes September 14, 2026. The offer stems from a cyberattack that exposed personal information for an estimated 35.8 million Comcast customers, and the flat payment is designed so that ordinary account holders can collect without proving they lost a dime. For older customers who rarely file claims, the calculation is simple: a few minutes on the official site now, or nothing after the deadline passes.
What the $117.5 million Comcast settlement covers
The settlement resolves claims tied to a breach that hit Comcast in October 2023 through a vulnerability in software from a third-party vendor. Intruders reached the systems over a span of days, and the exposed data ran well beyond names and email addresses. According to the case, the compromised information included usernames, contact details, dates of birth, partial Social Security numbers, and even the answers to account security questions, the kind of details that fuel identity theft and targeted scams for years after the fact.
Comcast did not admit wrongdoing, and the $117.5 million fund settles the litigation, known as Hasson v. Comcast Cable Communications, without a trial. Eligibility generally traces to whether Comcast notified a customer, around late 2023, that their Xfinity data had been exposed. Those notification letters are the practical dividing line between who can file and who cannot, which is why customers who kept that notice, or remember receiving it, are best positioned to claim.
The vulnerability at the center of the case has a name of its own. The intruders exploited a flaw in Citrix networking software widely known as “Citrix Bleed,” a bug that let attackers slip past login protections and pull session data out of affected systems, and that touched a long list of organizations in late 2023 before it was patched. In Comcast’s case the exposure ran over several days that October, long enough for the attackers to reach the stored account information at issue. For a claimant, that detail is useful mainly as evidence the breach was real and broad rather than a nuisance notice to discard, which is the frame that keeps the flat $50 from going unclaimed.
Free retirement updates: A quiet rule change can shrink a Social Security or Medicare check, and no one warns you. The free Retirement Shield newsletter catches these early and explains what to do. Get it free.
The $50 flat payment versus documented losses up to $10,000
The settlement offers two paths, and they are not stacked. A class member can take the flat $50 cash payment without submitting any proof, the simplest route and the one most account holders will use. Alternatively, a customer who suffered real financial harm traceable to the breach can claim up to $10,000 for documented losses, plus reimbursement for lost time at a rate of $30 an hour, but that route requires records such as bank statements, fraud reports, or receipts showing the harm.
For most retirees, the flat $50 is the sensible choice precisely because it demands nothing. Chasing the larger figure only makes sense for someone who can actually document fraud, unauthorized charges, or the cost of a credit freeze tied to this specific breach, and who is willing to assemble the paperwork. Padding a documented-loss claim is a bad idea: settlement administrators can deny or audit claims, and an unsupported figure can cost a filer the payment entirely.
The amount a flat-payment claimant ultimately receives can also shift with the volume of claims, since the fund is finite and lawyers’ fees and administrative costs come out before distribution. The $50 is the stated flat payment, but the practical takeaway is to claim what one is entitled to now rather than assume the money will still be there, or larger, later.
How to file before the September 14 deadline, and avoid the copycats
Claims must be submitted through the official settlement administrator by September 14, 2026, with online filings due and mailed claim forms postmarked by that date. The administrator’s site for the case is where the claim form lives, and it asks for basic identifying information to match a filer to the notified class. There is no fee to file, and no legitimate part of the process requires a payment, a gift card, or an upfront charge to release the money.
That last point is where older customers face the real hazard. Large, well-publicized settlements draw a wave of imitation sites and phishing calls that mimic the official process to harvest Social Security numbers and bank details. A caller claiming to “help” file, a text with a shortened link, or an email demanding sensitive data to “verify” a claim are the classic tells of a scam riding on the settlement’s name rather than the settlement itself.
The clean approach is to reach the official administrator directly, file the flat-payment claim if that fits, and ignore any third party asking for money or extra personal data. The settlement is real and the $50 is genuine, but the deadline is fixed and the fraud attempts circling it are just as real, which makes filing early through the official channel the version of this that ends with money in hand rather than a new identity-theft problem.
This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.
More Financial Reading