HomeSecurityComcast Xfinity accounts hacked - 2FA bypass

Comcast Xfinity accounts hacked – 2FA bypass

Comcast Xfinity customers are reporting that their accounts have been compromised in attacks that bypass two-factor authentication (2FA) . The compromised accounts are then used to reset passwords for other services, including crypto exchanges Coinbase and Gemini .

Comcast Xfinity accounts

On December 19, Xfinity email users began receiving notifications informing them that their account information had been changed . However, when they tried to log in to their accounts, they found that they were unable to access them because their passwords had been changed.

See also: LastPass: Hackers stole customer vault data

After restoring their accounts, they realized that someone had infiltrated them and added a secondary email at the temporary domain @yopmail.com.

Like Gmail, Xfinity offers customers the ability to set a secondary email address to be used for account notifications and password resets in case they lose access to their Xfinity accounts.

Many Comcast Xfinity customers shared their experiences on Reddit, Twitter, Bleeping Computer, and Xfinity's own support forum , which is how the account breaches became known

“Someone was able to reset my password and change my account details, bypassing 2FA. The email they set up was xxxxxxxx@yopmail.com,” an Xfinity customer explained on Reddit.

Bypass 2FA

A researcher told BleepingComputer that the attacks on Xfinity accounts are being carried out through credential stuffing to guess login credentials. Credential stuffing is a type of attack where cybercriminals use stolen usernames and passwords to gain access to previously compromised accounts. This method has become increasingly popular due to the availability of data on “underground” marketplaces, which makes it easier for hackers to purchase stolen credentials.

See also: Two men hacked JFK airport's taxi dispatch system

In the case of Xfinity, once hackers gain access to the account and are prompted to enter the 2FA code, the attackers allegedly use a private OTP bypass for the Xfinity website that allows them to forge successful 2FA verification requests.

Once they log in to the account, they can change the secondary email to the @yopmail.com account and perform reset password.

The primary email of Xfinity will be notified that its details have been modified, but users will not be able to gain access, as the password has also been changed.

Xfinity 2FA
Comcast Xfinity accounts hacked – 2FA bypass

After infiltrating an Xfinity email account, malicious actors quickly attempt to break into other services associated with the customer. To confirm their success in gaining access, they use the compromised emails.

According to comments from victims on BleepingComputer, the hackers attempted to reset passwords for multiple websites such as DropBox, Evernote, and even some crypto exchanges, such as Coinbase and Gemini.

See also: Nio hacked – hackers are holding it for ransom

A Comcast Xfinity customer reported on Reddit that the company is aware of the breaches and is looking into the source of the intrusions.

"I spoke to a person in xfinity security who told me not to worry about the fraudulent yopmail account on my xfinity account and pointed out that this has happened to many (maybe all) xfinity accounts," one user posted on Reddit.

“He said xfinity is still working to find the source of the breach. Apparently this is a much more widespread issue than is being reported. It doesn’t appear that xfinity email is secure at this time,” the user said.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS