Comcast to Pay $117.5 Million Over Data Breach Affecting Up

to 31.7 Million Customers

Comcast has agreed to pay $117.5 million to resolve class-action claims stemming from a 2023 cybersecurity breach that potentially affected as many as 31.7 million customers. A federal judge has granted final approval to the settlement, bringing a major legal chapter of the incident to a close.

The breach involved exploitation of the Citrix Bleed vulnerability in software Comcast used for remote access. According to the reported allegations, hackers gained access between October 16 and October 19, 2023, with affected customers notified roughly two months later.

What Happened in the Comcast Breach?

The incident centered on a vulnerability known as Citrix Bleed, which affected Citrix's NetScaler remote-access technology.

According to allegations in the lawsuit, attackers exploited the vulnerability in software used by Comcast during October 2023.

Plaintiffs alleged that Comcast failed to apply the available security patch within a reasonable timeframe, while Citrix was accused of shortcomings involving the testing and oversight of its software. Comcast and Citrix disputed the allegations.

The incident ultimately exposed sensitive customer information.

What Customer Information Was Exposed?

The compromised information reportedly included:

  • Names
  • Contact information
  • Dates of birth
  • Partial Social Security numbers
  • In some cases, full Social Security numbers
  • Driver's license numbers

The plaintiffs argued that the exposure created risks including identity theft, fraudulent activity and continuing financial harm.

The nature of the information involved made the breach particularly serious because Social Security numbers and driver's license information can potentially be used for identity-related fraud.

$117.5 Million Settlement Approved

Under the settlement, Comcast will establish a $117.5 million settlement fund.

The official settlement website says the fund is intended to cover:

  • Cash payments to eligible class members
  • Reimbursement for documented out-of-pocket losses
  • Lost-time claims
  • Identity-defense services
  • Restoration services
  • Notice and administration costs
  • Court-approved attorneys' fees and expenses
  • Service awards

Importantly, Comcast denies wrongdoing and denies violating the law. The settlement resolves the litigation without the court making a finding that Comcast was legally responsible for the alleged harm.

Customers Could Receive Up to $10,000

Eligible class members may seek reimbursement for documented losses related to the breach, with the settlement providing for claims of up to $10,000 per person for qualifying documented losses.

Alternatively, eligible customers can choose an estimated $50 alternative cash payment, subject to a possible pro-rata adjustment depending on the number and value of valid claims.

The settlement also provides access to identity-defense and restoration services.

September 14 Is the Key Claims Deadline

For customers who are eligible to participate, the most important upcoming date is:

September 14, 2026

Eligible class members must submit their claim online by that date or ensure a mailed claim is postmarked by the deadline.

Customers who do nothing will remain part of the settlement class but generally will not receive a settlement payment, while eligible identity-defense and restoration services remain available after the settlement becomes final.

Who Is Covered?

The settlement class includes people in the United States and its territories who received an individual notification from Comcast regarding the October 2023 data breach.

Settlement documents indicate that the class contains approximately 31.7 million people.

A court filing states that the class list contains email addresses for approximately 29.8 million members, while around 1.9 million have postal addresses without corresponding email addresses.

Why the Court Approved the Settlement

U.S. District Judge John Younge approved the agreement after considering the complexity of the litigation.

The court noted challenges involving the difficulty of proving damages across such a large class and determining the appropriate duty of care surrounding personal information.

The settlement allows both sides to avoid the uncertainty, expense and duration of a full trial.

Attorneys' Fees Reach $31.7 Million

The court approved approximately $31.7 million in attorneys' fees, equivalent to 27% of the settlement fund, according to the report.

That leaves the settlement fund to cover the various benefits and administrative expenses established under the agreement.

The precise amount an individual claimant ultimately receives can depend on the type of claim submitted, documentation and the number of valid claims.

Free Identity Protection Is Also Included

Cash compensation isn't the only benefit.

Eligible class members are also entitled to access Identity Defense Services and Restoration Services.

The official settlement materials say these services are provided automatically as a benefit to settlement class members, with enrollment instructions and codes available to eligible individuals.

This is particularly relevant given the type of personal information involved in the breach.

Comcast Data Breach Settlement at a Glance

Metric Details
Settlement $117.5 million
Potential class members ~31.7 million
Breach period October 16–19, 2023
Vulnerability Citrix Bleed
Potential documented-loss claim Up to $10,000
Alternative cash payment Estimated $50, subject to adjustment
Attorneys' fees $31.7 million
Claims deadline September 14, 2026
Identity protection Included

Figures are based on the reported settlement and official settlement materials.

Why This Case Matters for Corporate Cybersecurity

The Comcast case highlights a broader issue facing large technology and telecommunications companies.

A single vulnerability in remote-access infrastructure can potentially expose information belonging to tens of millions of customers.

The financial consequences can extend far beyond the initial cost of fixing the vulnerability.

Companies can face:

Cyberattack

Customer notification

Regulatory scrutiny

Class-action litigation

Legal expenses

Settlement costs

Long-term reputational damage

For large organizations holding sensitive customer data, cybersecurity is therefore increasingly becoming a major financial and operational risk.

The Growing Cost of Data Breaches

The Comcast settlement also demonstrates how the financial consequences of cybersecurity incidents can continue for years.

The original intrusion occurred in 2023.

The settlement was finally approved in 2026.

That means a cybersecurity incident can create a multi-year legal and financial tail even after the technical vulnerability has been addressed.

For companies handling personal data, the lesson is straightforward:

A cybersecurity breach is not only an IT problem—it can become a balance-sheet problem.

What Customers Should Know

If you believe you received a Comcast breach notification, the official settlement website is the appropriate place to verify eligibility and review claim options.

Official Comcast Data Breach Settlement Website

The official site currently lists September 14, 2026 as the deadline for submitting a claim.

Customers should be cautious of unrelated websites or messages asking for payment or sensitive information to process a settlement claim.

The Bigger Technology Story

The Comcast case comes at a time when companies are increasingly dependent on remote-access software, cloud infrastructure and interconnected enterprise systems.

The same technologies that improve operational efficiency can also expand the potential attack surface for cybercriminals.

The incident therefore reinforces several cybersecurity priorities:

Patch Quickly

Security updates need to be deployed rapidly when critical vulnerabilities emerge.

Monitor Access

Remote-access systems require continuous monitoring for suspicious activity.

Minimize Data Exposure

Organizations should limit the amount of sensitive information accessible through individual systems.

Prepare for Breaches

Incident-response plans can reduce the time between detection and customer notification.

Maintain Compliance

Strong cybersecurity controls can also reduce regulatory and litigation risks.

Final Take

Comcast is paying $117.5 million to settle litigation stemming from a 2023 data breach that potentially affected 31.7 million customers. The incident involved exploitation of the Citrix Bleed vulnerability and allegedly exposed highly sensitive information, including Social Security numbers and driver's license details in some cases.

Eligible customers may claim reimbursement for qualifying documented losses of up to $10,000, or pursue an alternative cash payment estimated at $50, subject to adjustment. Identity-defense and restoration services are also included.

The case is a reminder that cybersecurity failures can have consequences long after an attack ends.

For companies, a software vulnerability can become a multimillion-dollar legal liability. For consumers, the incident highlights why protecting personal information—and monitoring for identity theft after a breach—remains critical.