Vendor dossier
Also known as Comcast Corp · Comcast Cable Communications LLC · Xfinity · Comcast Holdings
1 Comcast Center 1701 Jfk Blvd, Philadelphia, Pennsylvania, 19103, United States · 10K+ employees
Key people
Last updated: Jul 29, 2026, 05:11 PM · Partial / limited public data
Conditional
Comcast faces Elevated Risk due to a 2023 data breach exposing PII for nearly 36 million customers, resulting in a $117.5M class-action settlement with ongoing… Limited public data - verify before relying.
Risk Tier
Risk Score
Confidence
partial
Material Incidents
Comcast Corporation is a publicly traded multinational mass media and technology conglomerate headquartered in Philadelphia, Pennsylvania. Founded in 1963, it operates across forty states and the District of Columbia, serving as the largest U.S. internet service provider in 2025. The company reported $123.7 billion in revenue and employs over 10,000 individuals. Its operations span cable television, broadband, broadcasting, and enterprise networking solutions, with a strategic focus on bridging the digital divide and expanding bundled connectivity services.
Comcast offers a diversified portfolio including consumer broadband, cable television, and broadcasting services under the Xfinity brand. For enterprise clients, Comcast Business provides networking infrastructure, including the ActiveCore SDN platform and SD-WAN solutions designed to streamline multi-location operations. The company competes with major telecommunications and technology firms, focusing on integrated connectivity, cloud-adjacent networking, and managed services for commercial and residential markets.
Comcast maintains a multi-layer security program applied to product development and service performance, emphasizing technical and organizational controls. The company states it employs robust security measures to detect and mitigate criminal activity, alongside dedicated privacy centers for consumer and business data protection. However, public disclosures lack specific third-party security certifications or detailed compliance frameworks. Recent litigation highlighted vulnerabilities in third-party infrastructure management, prompting ongoing investments in security protocols and expert resources.
[breach] FBCS Cyberattack
Data breach impacting over 237K customers in 2024.
Oct 10, 2024, 12:00 AM · Source
[legal] $117.5M Class Action Settlement
Settlement agreed for 2023 breach with claims deadline extended to Sept 14, 2026.
Jan 1, 2024, 12:00 AM · Source
[breach] Xfinity Data Breach
Exploitation of Citrix NetScaler vulnerability exposed PII for ~36 million customers between Oct 16-19, 2023.
Oct 16, 2023, 12:00 AM · Source
Recent news centers on a significant October 2023 cybersecurity incident where a third-party exploited a Citrix vulnerability, compromising personal data for approximately 36 million Xfinity customers. The breach triggered consolidated class-action lawsuits alleging inadequate data protection, ultimately resulting in a $117.5 million settlement agreement. Claim submission deadlines have been extended into 2026, with final court approval hearings scheduled. Additional reports note a separate 2024 vendor-related breach impacting over 237,000 customers and an FCC settlement regarding subscriber PII exposure.
Content in this section is vendor-supplied and does not alter Vendorisk.ai's risk tier or evaluation.
No input sources recorded · Generated Jul 29, 2026, 05:11 PM
Every verdict stores the public sources retrieved for this run. Read our methodology.
No input sources were recorded for this evaluation.
AI-generated assessment based on publicly available sources. Verify critical findings before contractual reliance. Analysis is advisory, not a compliance attestation, and is subject to data availability.
Years in Business
-
Comcast faces Elevated Risk due to a 2023 data breach exposing PII for nearly 36 million customers, resulting in a $117.5M class-action settlement with ongoing claims. Allegations of inadequate security controls and limited public disclosure of specific compliance certifications warrant heightened scrutiny despite stated multi-layer security programs.