Comcast was affected by a data breach at Financial Business and Consumer Solutions (FBCS), a third-party agency providing collection-related services. The breach exposed personal data of approximately 238,000 customers, including names, addresses, Social Security numbers, dates of birth, and Comcast account details. The incident was the result of unauthorized network access and a ransomware attack at FBCS between February 14 and 26, 2024. Comcast ceased working with FBCS in 2020, but due to data retention requirements, FBCS still held Comcast customer data from around 2021. While FBCS has not observed misuse of the compromised data, Comcast offered one year of credit monitoring and identity protection services to impacted individuals.
TPRM report: https://scoringcyber.rankiteo.com/company/comcast
"id": "com000101324",
"linkid": "comcast",
"type": "Ransomware",
"date": "10/2024",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '238,000',
'industry': 'Telecommunications',
'name': 'Comcast',
'type': 'Company'}],
'attack_vector': 'Unauthorized Network Access, Ransomware',
'data_breach': {'number_of_records_exposed': '238,000',
'personally_identifiable_information': 'Names, addresses, '
'Social Security '
'numbers, dates of '
'birth, and Comcast '
'account details',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal data'},
'date_detected': '2024-02-26',
'description': 'Comcast was affected by a data breach at Financial Business '
'and Consumer Solutions (FBCS), a third-party agency providing '
'collection-related services. The breach exposed personal data '
'of approximately 238,000 customers, including names, '
'addresses, Social Security numbers, dates of birth, and '
'Comcast account details. The incident was the result of '
'unauthorized network access and a ransomware attack at FBCS '
'between February 14 and 26, 2024. Comcast ceased working with '
'FBCS in 2020, but due to data retention requirements, FBCS '
'still held Comcast customer data from around 2021. While FBCS '
'has not observed misuse of the compromised data, Comcast '
'offered one year of credit monitoring and identity protection '
'services to impacted individuals.',
'impact': {'data_compromised': 'Personal data of approximately 238,000 '
'customers, including names, addresses, Social '
'Security numbers, dates of birth, and Comcast '
'account details',
'identity_theft_risk': 'High'},
'response': {'communication_strategy': 'Comcast offered one year of credit '
'monitoring and identity protection '
'services to impacted individuals'},
'title': 'Comcast Data Breach via Third-Party Vendor',
'type': 'Data Breach'}