Current and former Xfinity customers have until September 14 to claim a flat $50 payment, with no documentation required, from Comcast’s $117.5 million settlement over a data breach that exposed the personal information of roughly 35 million people. The deadline, already pushed back a month from mid-August, is now the hard cutoff for a payout that requires only a few minutes and a membership identifier. The money is guaranteed for eligible filers who act, and forfeited entirely for those who let the window pass.
The breach and the settlement behind the checks
The payout resolves claims tied to a cyberattack in October 2023, when intruders exploited a software vulnerability to reach data held by Comcast, exposing information belonging to about 35 million current and former Xfinity subscribers. The company mailed and emailed notifications that December, and a wave of class-action litigation followed, consolidating into the single settlement now being distributed. The underlying flaw sat in a widely used piece of Citrix software rather than in Comcast’s own code, which is part of why the same 2023 breach rippled across many organizations that relied on the same product.
That litigation produced the $117.5 million settlement fund now being paid out. Eligibility runs to people who received the 2023 notice, which typically arrived with a unique settlement member identifier used to file. A claimant who kept the email or letter can enter the code and submit online; one who did not can still look up eligibility through the official settlement administrator. The identifier speeds the process but is not the only path to filing.
The deadline itself has already moved once, extended from August 14 to September 14, which underscores that the date is administratively fixed rather than a marketing hook. Online claims must be submitted by 11:59 p.m. Eastern time on the fourteenth, and mailed claim forms must be postmarked by the same day. After that, the fund closes to new filers.
Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.
Three ways to claim, and the tradeoffs between them
The settlement offers a tiered menu rather than a single check. The simplest option is a flat $50 cash payment that requires no proof of harm, making it the default choice for the large majority of eligible customers who never traced a specific loss to the breach. It is the closest thing the settlement offers to automatic money.
A second track pays for time rather than cash losses. A claimant who spent hours dealing with the fallout, freezing credit, disputing charges, or monitoring accounts, can request $30 per hour for up to five hours, a maximum of $150, provided the time is attested on the claim form. That path suits someone who took concrete protective steps but has no dollar figure to document.
The largest tier, up to $10,000, is reserved for claimants who can document out-of-pocket losses traceable to the breach, such as fraudulent charges or identity-theft expenses. That option demands records and is far narrower in reach, but for a victim who suffered real financial damage it dwarfs the $50 flat payment. The three tiers are mutually exclusive, so a filer chooses the one that matches the evidence available.
Choosing wisely comes down to evidence and effort. For the overwhelming majority who noticed no concrete harm, the flat $50 is the rational pick, because the higher tiers demand documentation that most people cannot assemble two years after the fact. The one caution is that selecting a documented-loss claim without the paperwork to back it can slow or sink the entire filing, so a claimant unsure of the records should default to the no-proof option rather than gamble on a larger award that requires proof they lack.
Why so much of the money will go unclaimed
The structure all but guarantees that most of the exposed population collects nothing. Data-breach settlements routinely see single-digit claim rates, because eligible people never open the notice, assume the payment is a scam, or forget before the deadline. With roughly 35 million customers exposed and a defined fund, low participation means the money simply is not distributed rather than divided into larger individual checks.
Older customers face an added hurdle that has nothing to do with eligibility. A settlement notice arriving by email two years after a breach can look indistinguishable from the impersonation scams that target the same age group, and legitimate caution can suppress valid claims. The safeguard is to file only through the official administrator’s site and never through a link in an unsolicited message demanding payment or bank details, since a genuine settlement asks a claimant to submit information, not to pay anything.
The dollar math also explains why acting matters. A $117.5 million fund spread across 35 million people would average only a few dollars each if everyone claimed, but because participation in these settlements is typically low, the filers who do come forward collect the full $50 rather than a diluted share. The fund is paid out to those who submit a valid claim, not divided evenly among all the eligible, and whatever goes unclaimed does not automatically reach the people who stayed silent.
For an eligible household, the calculus is straightforward once the authenticity check is passed. The flat $50 costs a few minutes and no documentation, the deadline is now weeks away rather than months, and an unfiled claim returns nothing. The only variable within the customer’s control is whether the claim is submitted before the September 14 cutoff arrives.
This article was researched and drafted with the assistance of artificial intelligence.
More Financial Reading