Judge Approves $117.5 Million Settlement in ‘Complex’ Comcast Data Breach Case

 A federal judge has approved a $117.5 million data breach settlement against Comcast Cable Communications.


Dgb-50 Dgb-51 Dgb-52 Dgb-57 Dgb-58 Dgb-59 Dgb-60 Dgb-65


The agreement represents one of the largest data breach settlement amounts and, with 31.7 million potential members, one of the largest classes in a data breach case.


Dgb-66 Dgb-67 Dgb-68 Dgb-73 Dgb-74 Dgb-75 Dgb-76 Dgb-81 Dgb-82 Dgb-83

The case also represents one of the more complex data breach cases to date, according to Judge John Younge of the U.S. District Court for the Eastern District of Pennsylvania who approved the settlement.


Comcast customers complained about a data breach that occurred between October 16 and October 19, 2023, when cybercriminals exploited the “Citrix Bleed” vulnerability in the Citrix NetScaler appliance that Comcast used to manage remote access by customers and contractors.


Dgb-84 Dgb-89 Dgb-90 Dgb-91 Dgb-92 Dgb-97 Dgb-98 Dgb-99 Dgb-100 Dgb-105 Dgb-106 Dgb-107 Dgb-108 Dgb-113 Dgb-114 Dgb-115 Dgb-116 Dgb-121 Dgb-122 Dgb-123

Comcast did not notify affected customers until December 18, 2023 — roughly two months after the intrusion.


The plaintiffs claimed that Comcast failed to timely install the patch Citrix had made available; that Citrix failed to adequately test and monitor its NetScaler pro


See more beautiful photo albums Here >>>

duct; and that both companies’ conduct exposed class members to actual and attempted identity theft, fraud, and a substantial risk of further injury.


According to the complaint, the breach exposed personal information including names, contact information, dates of birth, the last four digits of Social Security numbers, secret questions and answers, and, for some class members, full Social Security numbers and driver’s license numbers.


The plaintiffs asserted 23 causes of action, including state common law claims, state statutory claims, as well as claims under the federal Cable Communications Policy Act, which the class lawyers indicated was the first time this federal law had been invoked for a cable company data breach.


Comcast and Citrix denied all allegations of wrongdoing.


The settlement was ultimately reached through five separate mediation sessions. The court issued a preliminary approval in January.


The agreement releases both Comcast and Citrix from all class claims related to the data breach, but the $117.5 million common fund is being funded by Comcast.


Under the settlement, class members may submit claims up to $10,000 per person for reimbursement of out-of-pocket losses and lost time. As an alternative to itemized claims, class members may claim a $50 cash payment. All members get a free subscription to a credit monitoring service.

Đăng nhận xét

Mới hơn Cũ hơn

Support me!!! Thanks you!


Join our Team