Skip to main content

The Money Overview

Comcast is paying $117.5 million to customers caught in a 2023 data breach — claim $50 with no proof, or up to $10,000 with receipts, by August 14

Nearly 36 million Xfinity customers had their personal data stolen over four days in October 2023, and Comcast is now writing checks to settle the fallout. A class action settlement worth $117.5 million, filed in Wilkerson v. Comcast Cable Communications in the U.S. District Court for the Eastern District of Pennsylvania, covers anyone whose information was compromised during the breach. Affected customers can file for a flat $50 payment with zero documentation, or submit receipts for out-of-pocket losses up to $10,000. The claims submission deadline is August 14, and the window is already open at the official settlement website.

How the breach happened

Between October 16 and October 19, 2023, attackers exploited a critical vulnerability known as Citrix Bleed (CVE-2023-4966) to break into Comcast’s internal Xfinity systems. The flaw affected thousands of organizations worldwide that year, but Comcast’s breach stood out for sheer scale. A filing posted by Maine’s attorney general recorded 35,879,455 individuals affected, making it one of the largest consumer data breaches reported to any state regulator in 2023.

Comcast did not tell customers until December 18, 2023, two months after the intrusion. In its notification letter, the company said it had “recently determined that unauthorized parties accessed some information” and urged customers to reset their passwords. The stolen data included usernames and hashed passwords for every affected account. For a subset of customers, the damage went deeper: the last four digits of Social Security numbers, dates of birth, security questions and answers, and contact details were also taken, as the Associated Press reported in December 2023.

Hashed passwords are stored in encrypted form rather than plain text, which provides a layer of protection. But security researchers have long warned that weak or commonly reused passwords can still be cracked from hashes, particularly when attackers also hold personal identifiers like birthdates or partial Social Security numbers that help narrow the possibilities.

What the settlement offers

The $117.5 million fund creates two paths to a payout for eligible class members:

  • No-proof cash payment: Any eligible customer can claim a flat $50 without submitting documentation of specific losses.
  • Documented losses up to $10,000: Customers who spent money dealing with the breach, whether on credit monitoring services, fraudulent charges, or time spent resolving identity theft, can file for reimbursement with supporting receipts.

Claims can be submitted through the official settlement claims website before the August 14 claims submission deadline. Separate deadlines for objections or requests to opt out of the settlement may differ; those details are available on the settlement website and in the official court notice mailed to class members. As of June 2026, the settlement is awaiting final court approval, a step that must occur before any payments are distributed.

Comcast has publicly acknowledged both the breach and the settlement terms. In its public statements following the settlement announcement, the company said it takes “the security of customer information seriously” and that the agreement “provides meaningful relief to affected customers.”

One reality worth understanding: the math does not guarantee everyone gets the full $50. If all 35.9 million eligible customers filed at the minimum tier, the total would exceed $1.79 billion, more than 15 times the fund’s size. In practice, class action claim rates typically land in the low single digits, according to consumer law researchers. The actual per-person payout depends on how many people file. Attorney fees and administrative costs will also reduce the pool before checks go out, so filing early and completely is the best way to protect your share.

What Comcast already provided, and why it may not be enough

Shortly after disclosing the breach in December 2023, Comcast offered affected customers 12 months of free credit monitoring and identity theft protection through Experian. That offer was noted in the company’s notification letter filed with Maine regulators. For anyone who enrolled at the time, that monitoring expired by late 2024, leaving a gap that makes the settlement’s additional compensation especially relevant for customers still dealing with consequences.

Maine’s attorney general maintains a public breach notification database that independently confirms the 35,879,455 affected-individual count, the October 16 through 19 intrusion window, and the December 2023 consumer notice date. A broader data breach spreadsheet compiled by the state places the Xfinity incident among the largest in its records, notable for both its scale and the mix of credentials and partial identity data involved.

What you should do before August 14

Whether or not you plan to file a claim, several steps are worth taking now if you were an Xfinity customer during the breach window:

  • Change your Xfinity password if you have not done so since October 2023. Choose something unique that you do not use on any other site.
  • Enable multi-factor authentication on your Xfinity account and on any other account where you reused the same password. Because usernames and hashed passwords were both exposed, credential-stuffing attacks (where stolen login pairs are tested across dozens of services) remain a real risk nearly three years later.
  • Watch your bank and credit card statements for unfamiliar charges. Customers whose partial Social Security numbers were exposed face a higher risk of targeted phishing and identity fraud.
  • Check your mail and email for a settlement notice. Class members should have received a notice from the settlement administrator. If you were an Xfinity customer in October 2023 and did not receive one, you may still be eligible to file through the claims website.
  • File your claim before August 14. The no-proof $50 option takes only a few minutes. If you spent money on credit monitoring, fraud resolution, or related expenses, gather those receipts for a documented claim of up to $10,000.

Stolen data from 2023 does not expire

The Xfinity breach is not just a story about one company’s security failure. The Citrix Bleed vulnerability that enabled it was a zero-day flaw that caught major corporations, government agencies, and healthcare systems off guard in late 2023. Comcast happened to be the highest-profile consumer-facing victim, but the underlying weakness extended across critical infrastructure far beyond any single network.

For the nearly 36 million people whose data was taken, the settlement represents one of the few concrete remedies available. As of the settlement filings, no public reporting indicates that Comcast has identified the specific attackers or recovered the stolen data. That means the exposed information, including partial Social Security numbers for some customers, may still be circulating in criminal marketplaces as of June 2026.

State-level transparency has been one of the few bright spots. Maine’s breach notification requirements forced timely public disclosure and created an independent record that does not rely solely on Comcast’s own characterization of events. But regulators do not control the financial terms of private class action settlements, and the gap between what government filings document and what consumers actually need to know about their payout remains wide.

Filing a claim through the settlement website before the August 14 deadline is the most direct action any affected customer can take right now. The $50 no-proof option requires almost no effort, and for anyone who spent real money cleaning up after the breach, the documented path to $10,000 exists for exactly that reason.

Avatar photo

Daniel Harper

Daniel is a finance writer covering personal finance topics including budgeting, credit, and beginner investing. He began his career contributing to his Substack, where he covered consumer finance trends and practical money topics for everyday readers. Since then, he has written for a range of personal finance blogs and fintech platforms, focusing on clear, straightforward content that helps readers make more informed financial decisions.​


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.