Comcast has agreed to pay a $1.5 million fine to close a months-long investigation by the Federal Communications Commission (FCC) into a serious data breach discovered in February 2024. The incident, involving a company vendor system , led to the exposure of personal information of nearly 275,000 Comcast customers , sparking concerns about data security in the industry.

How the case started: Assault on a former colleague
Although the breach did not originate from Comcast's systems, the impact was significant. The hackers targeted Financial Business and Consumer Solutions (FBCS), a debt collection agency that Comcast had stopped working with in 2022. However, sensitive customer information remained on FBCS's servers.
See also: Russian hackers target American engineering firm
The attack occurred between February 14 and 26, 2024. Cybercriminals managed to extract data such as names, addresses, Social Security Numbers, dates of birth, and Xfinity account numbers – information that can be used for identification, financial fraud, or account hijacking.
Chain of errors and delayed updates
FBCS initially said the breach affected 1.9 million people, but that number was quickly revised upwards to 3.2 million in June and 4.2 million in July. At the same time, FBCS assured Comcast in March that none of its customers were affected.

However, on July 15, a full five months after the cyberattack, FBCS officially informed Comcast that 273,703 of its customers had ultimately fallen victim to the breach. At the same time, the collection agency was already facing bankruptcy proceedings, and it was not until August 2024 that it publicly admitted to the breach.
See also: Dartmouth College: Data breach via Oracle EBS
Comcast's obligations after the settlement
In addition to the fine, Comcast committed to a series of new measures to strengthen data protection across its provider network . The FCC-mandated compliance plan includes:
- Designation of a compliance officer to oversee security procedures.
- Conduct risk assessments on all external partners who manage customer data, every two years.
- Submit detailed progress reports to the FCC every six months for the next three years.
- Mandatory reporting of any new material violation within 30 days of its discovery.
- Ensuring that suppliers delete or protect data that is no longer needed, as required by Law.
What does the company say?
Despite the financial settlement, Comcast maintains it is not responsible for the incident. In a statement to Reuters, it stressed that were not its own systems and that FBCS was required to adhere to certain security standards.
See also: SitusAMC: Data breach affects customers

The size of Comcast and the importance of the case
Comcast, one of the largest multinationals in the telecommunications, entertainment and media sectors, employs over 182,000 people and serves hundreds of millions of subscribers worldwide. With revenues reaching $123.7 billion in 2024, it is the fourth largest telecommunications provider in the world.
The case highlights the increasing complexity of supply chains in the digital world and how vulnerable even the largest companies can become when third-party partners do not maintain adequate security measures.
The FCC's message
The decision sends a clear message to the entire industry: the responsibility for data protection does not stop at the company's gate. Suppliers, partners and subcontractors are now critical links in a chain that must remain secure at every level.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
