Comcast $117.5M Xfinity Data Breach Settlement Wins Final Approval, Fee Award Cut

Independently fact-checkedBy Recording Law Editorial Team14 min read

Independently fact-checked against primary sources (last audited August 27, 2026). · 3 primary sources cited on this page. How we verify our legal content

Comcast $117.5M Xfinity Data Breach Settlement Wins Final Approval, Fee Award Cut

Frequently Asked Questions

Has the Comcast Xfinity data breach settlement received final approval?

Yes. U.S. District Judge John Milton Younge entered an order on August 20, 2026 in case No. 2:23-cv-05039-JMY (E.D. Pa.) approving the settlement as fair, reasonable, and adequate, overruling all objections, and dismissing the action with prejudice. The order was granted in part and denied in part only as to the amount of attorneys' fees requested.

What is the claim deadline for the Comcast settlement?

The court's August 2026 memorandum states that the claims deadline is September 14, 2026. The settlement administrator's site blocks automated requests, so recordinglaw.com could not cross-check it there; confirm the deadline at the official settlement site named in your notice. Once that date passes, no new claims can be submitted.

How much did the judge award in attorneys fees?

The order states the court granted attorneys' fees of $31,725,000.00, described in the order as 27 percent of the settlement fund. That is lower than the $39,166,666.67 one-third fee class counsel requested, a figure the order itself recites.

What caused the Comcast Xfinity data breach?

Comcast has said attackers exploited the "Citrix Bleed" vulnerability (CVE-2023-4966) in Citrix NetScaler software Comcast used for remote access, gaining unauthorized access to internal systems between October 16 and October 19, 2023.

What information was exposed in the Comcast breach?

Comcast's own notice describes usernames and hashed passwords as affected for impacted accounts, with names, contact information, the last four digits of Social Security numbers, dates of birth, and secret-question answers involved for some customers.

Do I need to file a claim to get free credit monitoring from this settlement?

No. The court's memorandum states that every settlement class member is entitled to enroll in at least three years of identity monitoring and restoration services without submitting a claim form, using the individual activation code included in the notice. Check the activation instructions in your own notice at the official settlement site.

When will settlement payments be sent out?

No payment date has been reported. Distribution in class action settlements like this one typically does not begin until after final approval and the resolution of any appeal, so a payment timeline depends on whether an appeal is filed and how long it takes to resolve.

Is recordinglaw.com the settlement administrator?

No. Recordinglaw.com is not the court, the settlement administrator, or a filing venue. This article is general legal information about a public court record. File any claim only at the official settlement website named in your notice.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. Order granting final approval in part and awarding $31,725,000 in attorneys' fees, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa. Aug. 20, 2026), ECF No. 322(storage.courtlistener.com)
  2. Memorandum accompanying the final approval order, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa. Aug. 20, 2026), ECF No. 321 (45 pp.)(storage.courtlistener.com)
  3. Preliminary Approval Order, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa. Jan. 16, 2026), ECF No. 278(storage.courtlistener.com)
  4. Public docket, Hasson v. Comcast Cable Communications LLC, No. 2:23-cv-05039-JMY (E.D. Pa.), via CourtListener RECAP(courtlistener.com)
  5. Official Comcast data breach settlement website (Kroll Settlement Administration), the only venue for filing a claim(comcastbreachsettlement.com)
  6. Pennsylvania Act 33 of 2024 (SB 824), Breach of Personal Information Notification Act amendments, approved June 28, 2024, effective September 26, 2024(legis.state.pa.us).gov
  7. Pennsylvania Breach of Personal Information Notification Act, Act of Dec. 22, 2005, P.L. 474, No. 94(legis.state.pa.us).gov
  8. NIST National Vulnerability Database, CVE-2023-4966 (Citrix NetScaler ADC and Gateway sensitive information disclosure, 'CitrixBleed')(nvd.nist.gov).gov
  9. Comcast, 'Notice To Customers of Data Security Incident,' Dec. 18, 2023 (the company's own breach notice)(businesswire.com)
Share: