Comcast will pay eligible Xfinity customers as much as $10,000 apiece, or a no-paperwork $50 flat rate, after a federal judge approved a $117.5 million settlement over an October 2023 data breach that exposed the personal information of roughly 35.8 million subscribers. The deadline to file a claim is September 14, 2026, a month later than the original August 14 cutoff. Anyone who received a Comcast breach notice in December 2023 already qualifies as a class member; the only open question left is whether they file before the window closes for good.
What Hackers Took From 35.8 Million Xfinity Accounts
According to the settlement notice, the breach ran from October 16 to October 19, 2023, when an unauthorized third party gained access to Comcast’s internal systems and extracted customer data before the intrusion was detected and shut down. The exposed records included usernames, contact information, dates of birth, account passwords, partial Social Security numbers, and the security-question answers customers use to verify their identity — the exact combination of data identity thieves use to open new credit lines, reset other accounts, or file fraudulent tax returns.
The case, Hasson v. Comcast Cable Communications LLC, moved through the U.S. District Court for the Eastern District of Pennsylvania for more than two years before the court held a final approval hearing on August 5, 2026, and formally approved the deal on August 20. Comcast denies any wrongdoing. Settlement class members are limited to people who received a breach notification letter or email around December 18, 2023, containing a unique settlement identification code — a narrower group than every Xfinity subscriber, but one the administrator still estimates at roughly 35.8 million people.
That mix of exposed data matters because it goes beyond the login credentials most breach notices involve. A partial Social Security number combined with a date of birth and a security-question answer is often enough for a fraudster to pass identity checks at a bank or a government agency, which is why the settlement pairs cash payments with free identity-monitoring coverage rather than compensation alone.
Free retirement updates: Social Security and Medicare change every year, and nobody sends you a memo. Our free Retirement Shield newsletter breaks down what changed and what to do. Get it free in your inbox.
A $50 No-Receipts Payment or Documented Losses Up to $10,000
Settlement class members choose between two payment tracks, and only one applies per claim. The simpler option is a flat $50 Alternative Cash Payment that requires no documentation at all; check a box on the claim form and the amount is folded into the payout automatically. The second option, reimbursement for documented losses, pays up to $10,000 per person for out-of-pocket costs tied directly to the breach — bank fees, replacement identification documents, and paid time spent freezing credit or disputing fraudulent charges.
Claiming the higher tier requires proof. The settlement instructs claimants to attach receipts, invoices, bank or credit card statements, or other records showing a specific dollar loss connected to the breach, and separately allows a claim for lost time — hours spent on the phone with a bank, credit bureau, or the IRS — compensated at a modest hourly rate up to the same $10,000 combined cap. Customers with no documented loss are limited to the $50 flat payment.
Neither number is a guaranteed check amount. The $117.5 million fund also has to cover notice and claims-administration costs, court-approved attorneys’ fees, and service awards for the named plaintiffs before any money reaches class members, and the settlement terms call for individual payments to be reduced pro rata if total approved claims exceed what remains in the fund. Every eligible customer, whether or not they file a claim, separately receives an automatic enrollment code for identity-defense and restoration services once the settlement takes effect.
The September 14 Deadline and the Two Dates Already Gone
The claims deadline is the only date still open. Customers who wanted to exclude themselves from the settlement, preserving their right to sue Comcast separately over the same breach, had to do so by July 1, 2026, and the window to formally object to the deal in court closed the same day. Both deadlines passed before the August 5 final approval hearing, meaning the roughly 35.8 million notified customers are now bound by the settlement’s terms whether or not they ever submit a claim.
Filing itself is straightforward. Class members can submit an online claim form through the settlement administrator or mail a paper form to Kroll Settlement Administration LLC in New York, and either version must be submitted or postmarked no later than September 14, 2026 — 11:59 p.m. Eastern time for the online portal. Anyone who misses that date forfeits any cash payment from the fund but keeps the free identity-monitoring benefit and gives up the right to sue Comcast independently over the same incident.
The court’s approval is not automatically final the moment the September 14 window closes. Comcast denied any wrongdoing throughout the litigation, and large data-breach settlements of this size routinely remain open to appeal for months after a judge signs off, which can delay when the settlement administrator actually cuts checks even after every eligible claim has been filed and verified.
Exactly how much money reaches any single household still depends on how many of the roughly 35.8 million eligible customers file before the deadline. Kroll Settlement Administration LLC has not published a running claims count, and because the fund is fixed at $117.5 million regardless of participation, the settlement’s own math means a lower turnout raises what each claimant collects while a rush of last-minute filings could push payments toward the $50 floor.
This article was produced with the assistance of AI and reviewed by The Money Overview editorial team before publication.
More Financial Reading