Comcast is paying $117.5 million to settle claims stemming from a 2023 data breach, following final approval of the agreement by a federal judge. The settlement resolves allegations affecting up to 31.7 million potential class members.
The security incident occurred when hackers exploited the Citrix Bleed vulnerability in software used by Comcast for remote access between October 16 and October 19, 2023. Affected customers received notifications two months later. Plaintiffs in the class-action lawsuit alleged that Comcast failed to apply Citrix’s security patch within a reasonable timeframe and that Citrix did not properly test and oversee its NetScaler software. According to the plaintiffs, these actions left individuals vulnerable to identity theft, fraudulent activity, and ongoing financial harm.
Data exposed during the breach included names, contact details, dates of birth, partial Social Security numbers, and in certain cases, full Social Security numbers and driver’s license numbers.
Under the terms of the settlement, class members are eligible to seek up to $10,000 each for documented losses or choose a $50 flat payment accompanied by free credit monitoring. Judge John Younge of the U.S. District Court for the Eastern District of Pennsylvania presided over the matter, noting in his ruling that the case is inherently complex due to challenges in proving class-wide damages and defining the duty of care owed regarding personal information.
The court also approved $31.7 million in attorneys’ fees, which accounts for 27% of the settlement fund. The agreement is funded entirely by Comcast and releases both Comcast and Citrix from related claims.


