Comcast disclosed that unauthorised access to internal systems occurred between 16 and 19 October 2023 through CVE-2023-4966, the Citrix NetScaler vulnerability filed at 23-1010. It reported identifying an anomaly on 25 October during a routine cybersecurity exercise and determining on 16 November that Xfinity customer information had been accessed.
The company put the affected population at more than 35.8 million customers. Reported data includes usernames and hashed passwords, and for some customers names, contact details, the last four digits of social security numbers, dates of birth and secret questions and answers.
Six Days Between Patch And Intrusion
Citrix published the fix on 10 October. The reported access ran from 16 October. Whatever the internal reason, the window between a patch being available and being applied was the whole of the exposure.
The corpus is careful here. Six days is not negligence by any published standard — it is faster than most organisations manage on most vulnerabilities. It is also, as 25-1216 puts it, longer than the window now exists.
The Detection Was A Scheduled Exercise
The anomaly was found during a routine cybersecurity exercise rather than by an alert. That is a better outcome than most files in this database — but it means detection happened on the exercise calendar, not on the attacker’s.
Three weeks then passed between finding the anomaly and establishing what customer data was involved, which is the ordinary shape of scoping work and the reason initial figures move, as recorded at 23-1117.
Secret Questions Are Not Resettable
Hashed passwords can be rotated and were. Security questions and answers cannot be meaningfully changed — the mother’s maiden name is the same next year — and they are used for account recovery across unrelated services.
The corpus files this reissuance boundary at 23-1204 for ancestry, 26-0324 for fingerprints and 23-0710 for identity fields. A stolen secret question is a permanent key to a door somewhere else.
Built on contemporaneous reporting of Comcast’s customer notification and disclosure. The 16–19 October access window, the 25 October anomaly detection, the 16 November determination, the 35.8 million figure and the data categories are the company’s own statements as reported. The underlying vulnerability and its patch date rest on the CISA guidance cited at 23-1010. No actor attribution is made: Comcast did not name one. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.