[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2hx5ndrbfoclv":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825158","comcast","Comcast Data Breach","comcast.net","2015-11-08T00:00:00.000Z","2016-02-08T21:41:43.000Z","2026-07-02T11:50:22.876Z","2026-07-18T23:48:18.475Z","Third party breach","https:\u002F\u002Fwww.ibtimes.co.uk\u002Fcomcast-data-breach-590000-customer-passwords-go-sale-dark-web-1528026",[15,17],"https:\u002F\u002Ftime.com\u002F4105920\u002Fcomcast-customer-information\u002F",616882,"known",null,"unknown","High",[24,25,26],"Email addresses","Passwords","Physical addresses","\u003Cp>The Comcast data breach record is associated with the sale of a large list of Comcast customers' email addresses and password values on underground forums in the period of November 2015. The number of affected accounts verified for this record is 616,882. In the incident, it was reported that approximately 590 thousand customer email address and password combinations were listed, and in addition, physical address information was present in about 27 thousand accounts. Therefore, the incident carries both the risk of account takeover and targeted fraud.\u003C\u002Fp>\n\u003Cp>This record should not be confused with a separate Xfinity security incident that occurred in 2023. The incident here pertains to the Comcast dataset dated November 8, 2015, and the verified data classes are email addresses, passwords, and physical addresses. The company stated at the time that it had not confirmed a direct breach of its own internal systems and that the data could have been collected through phishing, malware, or other leaks. Nevertheless, the presence of account combinations in the list poses a serious risk if users reuse the same password on other services.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data types are email addresses, password values, and physical addresses. The email and password combination is one of the most directly usable data types for an attacker. If a user has used the same password on different accounts, a single leak can turn into trial attacks on email, social media, shopping, financial, cloud storage, or work accounts. The password being listed in plain text means that the attacker can attempt automatic logins without needing a complex cracking process.\u003C\u002Fp>\n\u003Cp>The presence of physical address information in some records further increases the risk. When the combination of home address, email address, and password is used together, scenarios such as fake invoices, delivery notifications, subscription renewals, modem setups, support tickets, or payment reminders can become more convincing. Address information can also be used to build trust in social engineering. A message addressing the user based on where they live may appear more persuasive than a simple mass phishing message.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record covers 616,882 affected accounts. In the main part of the incident, there are approximately 590,000 email and password combinations, while in the additional section there are about 27,000 accounts with physical addresses. Therefore, the number seen in the system reflects the scope of different parts merged and deduplicated. The record date is kept as November 8, 2015; the addition and subsequent update dates may differ from the incident date.\u003C\u002Fp>\n\u003Cp>Verified data classes are email address, password, and physical address. In this record, social security number, date of birth, payment card, bank account, security question, username, or customer support conversation are not verified data classes. Additionally, there is no limitation regarding the source of the incident where the company acknowledges unauthorized access directly to its own systems. Therefore, the record should be evaluated as a dataset of Comcast account data that has circulated and is verified in terms of user security, rather than the claim that it was 'definitely stolen from Comcast systems.'\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The group at highest risk is users who reuse the password they use for their Comcast account on other accounts. The same email and password combination may be tried on different services; this poses a risk especially for old email accounts, non-online banking financial services, shopping sites, streaming platforms, and social media accounts. Even if the password is old, if the user has maintained it elsewhere with small changes, attackers may try similar variations.\u003C\u002Fp>\n\u003Cp>Users whose physical addresses are listed may encounter more targeted fraud attempts. Messages claiming to be about internet subscription, modem replacement, service appointments, bill discounts, parcel delivery, or address verification should be examined carefully. Knowing the home address correctly does not make the message trustworthy. If family members use the same address and similar email patterns, attackers may also target household members. Therefore, the risk may extend not only to a single account but also to the online security of people living at the same address.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>In this record, the user who sees a match should first change the password used for their Comcast account and then update other accounts where the same or similar password is used one by one. New passwords should be unique and long, and if possible, generated with a password manager. The email account should be especially protected since it is the central point for password reset links. Multi-factor authentication should be enabled for the email account, and the session history and forwarding settings should be checked.\u003C\u002Fp>\n\u003Cp>Users with a physical address should be more skeptical of subscription or invoice-related messages. Unexpected links should not be opened, and verification codes, passwords, payment information, or remote access permissions should not be shared in incoming phone calls. When a transaction using the name Comcast or Xfinity is required, the user should manually type the official domain they know to carry out the transaction. The risk should not be assumed to be over just because it was an old incident; email and password combinations can be used in brute force attacks even years later.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Comcast incident shows that old password lists remain important for account security even years later. Users should use unique passwords for each service, not reuse old passwords, and enable additional verification on critical accounts. Using a password manager makes it easier both to generate unique passwords and to track where old passwords have been used. In particular, email accounts, phone carrier accounts, and internet subscription panels should be protected separately.\u003C\u002Fp>\n\u003Cp>In leaks containing address information, a long-term strategy is not limited to just changing passwords. Users should see fake invoice, fake technical service, modem renewal, delivery notification, and subscription renewal messages as a permanent risk. This risk should also be explained to other people in the household, because fraud messages can be directed not only to the person in the leak but also to someone else living at the same address. When data from old leaks is combined with other datasets, more convincing attacks may emerge.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The fact that a match is found in this record indicates that the relevant email address was among the accounts seen in the 2015 Comcast dataset. A match does not mean that the user's current Comcast or Xfinity account has been compromised today; however, it indicates that the password used in the past and, if applicable, the address information may have been exposed. Therefore, the user's priority should be to stop reusing the password and ensure that the same combination is not used on other accounts.\u003C\u002Fp>\n\u003Cp>The user should first update their Comcast account and any other accounts that use the same password. Then, they should enable additional verification on their email account, review security notifications, and close suspicious sessions. In cases where physical address information may have been leaked, the user should verify requests coming under the pretext of address verification or service appointments through a separate channel. Even if the incident is old, exposed password combinations and address information can be used for a long time in phishing and account takeover attempts.\u003C\u002Fp>","","Comcast Data Breach (616.9 Thousand Reported Records)","Comcast Data Breach. 616.9 Thousand reported records were reported. Reported data: Email addresses, Passwords, Physical addresses. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fcomcast_net.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":20},"Comcast","Telecommunications","United States"]