Comcast $117.5M Xfinity Data Breach Settlement Wins Final Approval, Fee Award Cut
Independently fact-checked against primary sources (last audited August 27, 2026). · 3 primary sources cited on this page. How we verify our legal content

Comcast's $117.5 Million Xfinity Breach Settlement Wins Final Approval; Court Cuts Fee Award to $31.7 Million
A federal judge in Pennsylvania approved the $117.5 million Comcast Xfinity data breach settlement on August 20, 2026 and awarded class counsel $31,725,000 in fees, less than they asked for. The single docket order disposing of both motions is worded as granted in part and denied in part.
Information last verified on August 27, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article addresses the consolidated federal class action Hasson v. Comcast Cable Communications LLC, Master File No. 2:23-cv-05039-JMY, in the U.S. District Court for the Eastern District of Pennsylvania, which also named Comcast Corporation, Citrix Systems, Inc., and Cloud Software Group, LLC as defendants and released all of them. The court dismissed the action with prejudice and directed entry of final judgment on August 20, 2026. It does not address any separate state regulatory enforcement tied to the same breach. For the settlement's claim process and deadlines, see our Comcast Xfinity settlement tracker.
What Happened
U.S. District Judge John M. Younge of the Eastern District of Pennsylvania entered two docket entries on August 20, 2026, both dated August 19, 2026 in the documents themselves,, in Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039: a 45-page memorandum (entry 321) and a one-page order (entry 322). The order's docket text states that the plaintiffs' motion for final approval of the class action settlement (document 315) and their motion for attorneys' fees, costs, expenses, and service awards (document 286) "ARE GRANTED IN PART AND DENIED IN PART," and that the court "GRANTS ATTORNEY'S FEES OF $31,725,000.00 (27% OF THE SETTLEMENT FUND)." The docket text as entered contains several typographical errors (it reads "ACCOMPYING," "PLANTIFF'S," and "EXPESNES"); recordinglaw.com is quoting it verbatim rather than silently correcting it. The case is a consolidated class action over a 2023 data security incident that Comcast disclosed to Xfinity customers; the order itself itemizes the disposition in two numbered paragraphs: the motions are denied insofar as they request attorneys' fees of $39,166,666.67, one-third of the $117.5 million settlement fund, and are granted in all other respects.
The order itself states what was requested: class counsel sought attorneys' fees of $39,166,666.67, one-third of the $117.5 million fund, and the court awarded $31,725,000 instead, a reduction of $7,441,666.67. The memorandum works through the Third Circuit's Gunter and Prudential factors and finds that only one of them, awards in similar cases, weighs against the request, noting that fee awards in data breach cases have generally run between 20 and 30 percent, that 25 percent is a common benchmark, and that percentage fees in very large recovery cases are appropriately smaller in percentage terms. A lodestar cross-check against class counsel's $9,926,175 lodestar yields a multiplier of approximately 3.2.
The case traces to a data security incident Comcast disclosed on December 18, 2023. According to Comcast's own notice, unauthorized access to internal systems occurred between October 16 and October 19, 2023, after attackers exploited "Citrix Bleed" (CVE-2023-4966), a vulnerability in Citrix NetScaler software that Comcast used to manage remote access. Comcast has said it found suspicious activity during a routine cybersecurity exercise on October 25, 2023, determined by November 16 that data had likely been taken, and identified the specific categories of exposed information by December 6, 2023, before notifying customers on December 18. Comcast's notice describes usernames and hashed passwords as compromised for affected accounts, and says that for some customers the exposure also included names, contact information, the last four digits of Social Security numbers, dates of birth, and secret-question answers. The operative complaint, as summarized by the court, further alleged that full Social Security numbers and driver's license numbers were acquired for some class members. State breach filings reported by trade press have carried a higher figure for total individuals affected, which recordinglaw.com did not verify against a primary source; the settlement class itself is defined more narrowly, and the court's memorandum puts the settlement class at approximately 31.5 million members, defined as all persons residing in the United States and its territories who were sent individual notification of the breach.
The case had already cleared several procedural steps before the August 20 order. A deadline to exclude oneself from the class or object to the settlement passed July 1, 2026, and a final approval hearing was held August 5, 2026. The claim-filing window is separate from all of that; the court's memorandum states that the claims deadline is September 14, 2026, after which no new claims can be submitted. The preliminary approval order entered January 16, 2026 had originally set an August 14, 2026 claims deadline, which is why some earlier coverage carries that date.
What the Law Actually Says
Final approval in a federal class action follows Federal Rule of Civil Procedure 23(e): a court may approve a class settlement only after finding it is fair, reasonable, and adequate, considering factors that include the adequacy of representation, the arm's-length nature of the negotiations, the relief provided for the class, and how class members responded to notice, including objections. A "granted in part and denied in part" disposition on a combined approval-and-fee motion is not unusual: courts frequently approve the settlement itself while adjusting the piece asking for the largest attorneys' fee award, since the fee request is reviewed independently of whether the underlying deal is fair to the class.
Attorneys' fees in a common-fund settlement like this one, where the money that pays the fee comes out of the same $117.5 million paying class members, are typically set as a percentage of the fund. Here the court noted that notice and administration costs above $7.3 million are paid separately by Comcast rather than deducted from the fund, and that the fund is non-reversionary, so nothing left over goes back to Comcast. Percentage fees are with courts in this circuit weighing that percentage against the results achieved, the risk counsel took on, and the complexity of the litigation. A court cutting a requested percentage, as this order describes, is one of the standard checks against a fee award that would otherwise reduce what is left for the class.
Separately, Pennsylvania's own data breach law is relevant background because Comcast is headquartered in Philadelphia and the case is pending in the state's federal district. Pennsylvania's Breach of Personal Information Notification Act, first enacted in 2005, requires private entities to notify affected residents "without unreasonable delay." The law was substantially strengthened by a 2024 amendment that added mandatory Attorney General notification for breaches affecting more than 500 Pennsylvania residents and required access to a credit report plus 12 months of free credit monitoring when a Social Security number, bank account number, or driver's license or State ID number is involved, but those amendments took effect September 26, 2024, nearly a year after Comcast's October 2023 breach and the December 2023 notice, so they did not govern how this particular incident had to be reported. For more on what the law requires today, see our guide to Pennsylvania's data privacy and breach notification rules.
What Happens Next
Final approval is not the end of the case procedurally. Distribution of settlement funds to class members typically does not begin until the period to appeal the final approval order has run, and any appeal that is filed is resolved. The memorandum dismissed the action with prejudice and directed the Clerk to enter final judgment, which is the event that starts the appeal clock. As reviewed on August 27, 2026, the public RECAP mirror of this docket showed no entries after the August 20, 2026 order and no notice of appeal; RECAP mirrors PACER and can lag it. That reflects the state of that mirror as of this review only; it does not rule out an appeal being filed within the applicable window, and a notice of appeal, if filed, would generally pause distribution until it is resolved.
Class members do not need to wait for that process to submit a claim. The court's August 2026 memorandum states that the claims deadline is September 14, 2026, a date the court recited while overruling an objection that misread the settlement's documentation requirement. Recordinglaw.com could not also cross-check that date against the settlement administrator's own site, which returned an automated access error (HTTP 403) on repeated attempts on August 27, 2026; a blocked fetch is not a contradiction. If you are reading this on or after September 14, 2026, the court-set claim window has closed and no new claims can be submitted. Anyone trying to file a claim or confirm the deadline should go directly to the official settlement site named in their notice email or letter, not to a third-party search result.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
A fee reduction attached to a final approval order is a routine, built-in check in class action practice, not a sign that anything went wrong with the settlement itself. Judges reviewing common-fund fee requests are expected to test the percentage counsel is asking for against what the litigation actually achieved, and a downward adjustment like the one reported here is exactly what that review is for. Reading a trimmed fee award as a rebuke of the underlying deal would overstate what the docket text actually shows.
What is more notable is the scale involved. A settlement class in the tens of millions and a fund near $117.5 million puts this case among the larger data breach settlements to reach final approval, in the same range as other large breach deals we have covered, including how the 23andMe genetic-data breach settlement was structured. For a breach that traces back to a single unpatched remote-access appliance, the size of the eventual settlement is a useful data point for any organization weighing how quickly to patch a disclosed vulnerability against the cost of doing so later.
How This Affects You
If you received a notice about this breach in December 2023 with a settlement member ID, the final approval order does not change your options: you can submit a claim while the court-set window remains open, which the court's memorandum puts at September 14, 2026; after that date the window is closed and no new claims can be submitted. Being part of the settlement does not require you to prove anything happened to you personally to claim the settlement's alternative cash payment, which the court's memorandum describes as $50 subject to pro rata adjustment depending on how many valid claims are filed, with just under 1 million claims received as of July 15, 2026. The court's memorandum states that every settlement class member is entitled to enroll, without submitting a claim form, in at least three years of identity monitoring and restoration services, using an individual activation code that was included in the notice. If that applies to your notice, enrolling in that free benefit and placing a free security freeze on your credit files are reasonable first steps that cost nothing, before considering any paid identity-protection product; our guide covers the warning signs that your identity has already been misused if you want to check further. This is general information about how the process works, not a determination of your eligibility or an estimate of what you personally would receive; only the settlement administrator's records can tell you that.
This is general legal information, not legal advice. It covers a federal case pending in the Eastern District of Pennsylvania and reflects sources verified on August 27, 2026. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- track the status of this settlement on our Comcast Xfinity tracker
- how the 23andMe data breach settlement compares
- Pennsylvania's data privacy and breach notification rules
- warning signs your identity has already been misused
Last updated: 2026-08-27. This is a developing story; details verified as of 2026-08-27.
Frequently Asked Questions
Has the Comcast Xfinity data breach settlement received final approval?
Yes. U.S. District Judge John Milton Younge entered an order on August 20, 2026 in case No. 2:23-cv-05039-JMY (E.D. Pa.) approving the settlement as fair, reasonable, and adequate, overruling all objections, and dismissing the action with prejudice. The order was granted in part and denied in part only as to the amount of attorneys' fees requested.
What is the claim deadline for the Comcast settlement?
The court's August 2026 memorandum states that the claims deadline is September 14, 2026. The settlement administrator's site blocks automated requests, so recordinglaw.com could not cross-check it there; confirm the deadline at the official settlement site named in your notice. Once that date passes, no new claims can be submitted.
How much did the judge award in attorneys fees?
The order states the court granted attorneys' fees of $31,725,000.00, described in the order as 27 percent of the settlement fund. That is lower than the $39,166,666.67 one-third fee class counsel requested, a figure the order itself recites.
What caused the Comcast Xfinity data breach?
Comcast has said attackers exploited the "Citrix Bleed" vulnerability (CVE-2023-4966) in Citrix NetScaler software Comcast used for remote access, gaining unauthorized access to internal systems between October 16 and October 19, 2023.
What information was exposed in the Comcast breach?
Comcast's own notice describes usernames and hashed passwords as affected for impacted accounts, with names, contact information, the last four digits of Social Security numbers, dates of birth, and secret-question answers involved for some customers.
Do I need to file a claim to get free credit monitoring from this settlement?
No. The court's memorandum states that every settlement class member is entitled to enroll in at least three years of identity monitoring and restoration services without submitting a claim form, using the individual activation code included in the notice. Check the activation instructions in your own notice at the official settlement site.
When will settlement payments be sent out?
No payment date has been reported. Distribution in class action settlements like this one typically does not begin until after final approval and the resolution of any appeal, so a payment timeline depends on whether an appeal is filed and how long it takes to resolve.
Is recordinglaw.com the settlement administrator?
No. Recordinglaw.com is not the court, the settlement administrator, or a filing venue. This article is general legal information about a public court record. File any claim only at the official settlement website named in your notice.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Order granting final approval in part and awarding $31,725,000 in attorneys' fees, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa. Aug. 20, 2026), ECF No. 322(storage.courtlistener.com)
- Memorandum accompanying the final approval order, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa. Aug. 20, 2026), ECF No. 321 (45 pp.)(storage.courtlistener.com)
- Preliminary Approval Order, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa. Jan. 16, 2026), ECF No. 278(storage.courtlistener.com)
- Public docket, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa.), via CourtListener RECAP(courtlistener.com)
- Official Comcast data breach settlement website (Kroll Settlement Administration), the only venue for filing a claim(comcastbreachsettlement.com)
- Pennsylvania Act 33 of 2024 (SB 824), Breach of Personal Information Notification Act amendments, approved June 28, 2024, effective September 26, 2024(legis.state.pa.us).gov
- Pennsylvania Breach of Personal Information Notification Act, Act of Dec. 22, 2005, P.L. 474, No. 94(legis.state.pa.us).gov
- NIST National Vulnerability Database, CVE-2023-4966 (Citrix NetScaler ADC and Gateway sensitive information disclosure, 'CitrixBleed')(nvd.nist.gov).gov
- Comcast, 'Notice To Customers of Data Security Incident,' Dec. 18, 2023 (the company's own breach notice)(businesswire.com)