Desk live·
ForensicPost
Breaches/Telecom/File 23-1218

Comcast Says Citrix Bleed Reached Xfinity Data on 35.8 Million Customers

Citrix published a patch on 10 October. Comcast reported unauthorised access between 16 and 19 October, found an anomaly on 25 October during a routine exercise, and established on 16 November what had been taken. The patch existed for the whole of it.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetComcast Xfinity
ActorUnattributed
D. Kennedy10 min readConfidence: high2 sources reviewed

Comcast disclosed that unauthorised access to internal systems occurred between 16 and 19 October 2023 through CVE-2023-4966, the Citrix NetScaler vulnerability filed at 23-1010. It reported identifying an anomaly on 25 October during a routine cybersecurity exercise and determining on 16 November that Xfinity customer information had been accessed.

The company put the affected population at more than 35.8 million customers. Reported data includes usernames and hashed passwords, and for some customers names, contact details, the last four digits of social security numbers, dates of birth and secret questions and answers.

Six Days Between Patch And Intrusion

Citrix published the fix on 10 October. The reported access ran from 16 October. Whatever the internal reason, the window between a patch being available and being applied was the whole of the exposure.

The corpus is careful here. Six days is not negligence by any published standard — it is faster than most organisations manage on most vulnerabilities. It is also, as 25-1216 puts it, longer than the window now exists.

The Detection Was A Scheduled Exercise

The anomaly was found during a routine cybersecurity exercise rather than by an alert. That is a better outcome than most files in this database — but it means detection happened on the exercise calendar, not on the attacker’s.

Three weeks then passed between finding the anomaly and establishing what customer data was involved, which is the ordinary shape of scoping work and the reason initial figures move, as recorded at 23-1117.

Secret Questions Are Not Resettable

Hashed passwords can be rotated and were. Security questions and answers cannot be meaningfully changed — the mother’s maiden name is the same next year — and they are used for account recovery across unrelated services.

The corpus files this reissuance boundary at 23-1204 for ancestry, 26-0324 for fingerprints and 23-0710 for identity fields. A stolen secret question is a permanent key to a door somewhere else.

How we reported this

Built on contemporaneous reporting of Comcast’s customer notification and disclosure. The 16–19 October access window, the 25 October anomaly detection, the 16 November determination, the 35.8 million figure and the data categories are the company’s own statements as reported. The underlying vulnerability and its patch date rest on the CISA guidance cited at 23-1010. No actor attribution is made: Comcast did not name one. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Comcast’s Xfinity discloses massive data breach linked to CitrixBleed vulnerabilityCybersecurity Dive
  2. Citrix Bleed leveraged to steal data of 35+ million Comcast Xfinity customersHelp Net Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary