Skip to content

Comcast $117.5 mn data breach settlement wins federal approval

Comcast $117.5 mn data breach settlement wins federal approval

A federal judge has approved Comcast Cable Communications’ $117.5 mn settlement over a 2023 data breach affecting millions of customers.

The agreement ranks among the largest monetary settlements reached in US data breach litigation. With roughly 31.7 mn potential class members, it also covers one of the largest groups assembled in a cyber breach case.

Judge John Younge of the US District Court for the Eastern District of Pennsylvania described the litigation as unusually complex when approving the agreement.

The dispute traces back to a cyberattack between October 16 and October 19, 2023.

Attackers exploited the Citrix Bleed vulnerability in a Citrix NetScaler appliance Comcast used to manage remote access for customers and contractors. Comcast informed affected customers on December 18, about two months after the intrusion.

Customers alleged Comcast failed to install a security patch Citrix had already released in time to prevent the breach. Their claims against Citrix focused on its NetScaler product.

Plaintiffs alleged the company failed to test and monitor the technology adequately, exposing affected Comcast customers to identity theft attempts and fraud. They also claimed the breach created continuing risks for people whose information entered the attackers’ hands.

According to the complaint, compromised data included customer names and contact information. Dates of birth were also exposed.

For some customers, attackers obtained the last four digits of Social Security numbers along with security questions and answers. Other class members had full Social Security numbers or driver’s license numbers exposed.

The plaintiffs brought 23 causes of action against Comcast and Citrix. Those claims included state common-law theories and claims based on state statutes. Plaintiffs also invoked the federal Cable Communications Policy Act.

Class attorneys told the court they believed the lawsuit marked the first use of the Cable Act in litigation involving a cable company’s data breach.

Comcast and Citrix denied wrongdoing. The parties reached the settlement after five separate mediation sessions. The court granted preliminary approval in January before completing its final review.

Under the agreement, class members release Comcast and Citrix from claims connected with the breach. Comcast will fund the entire $117.5 mn settlement pool.

People documenting out-of-pocket expenses or lost time linked to the breach are eligible to seek reimbursement of up to $10,000 each. Class members who don’t submit itemized losses instead have the option of claiming a $50 cash payment.

Every eligible member also receives a free subscription to a credit-monitoring service.

Judge Younge approved $31.7 mn in attorneys’ fees, equal to 27% of the settlement fund. The court credited class counsel with resolving a technically difficult case within two years.

The judge wrote that data breach litigation presents difficult questions around class-wide damages. Courts also face unsettled questions about the legal duties companies owe when storing or protecting personal information.

This case presented additional legal problems beyond those commonly seen in breach lawsuits.

According to class counsel, courts had never applied the federal statute to a cable operator’s data breach. The case therefore raised unresolved questions over whether the compromised records qualified as personally identifiable information under the Cable Act.

Another issue concerned the sensitivity threshold required by the statute. The court would have needed to determine whether the exposed customer information satisfied that standard if the litigation continued.

Plaintiffs sought to hold a cybersecurity technology provider responsible for losses suffered by customers of one of its corporate clients. Citrix had no direct relationship with those Comcast customers and didn’t directly handle their personal information.

The dispute therefore raised the question of whether a cybersecurity vendor owes a duty of care to its customers’ end users. Judge Younge said no court within the Third Circuit had resolved that issue.

Those unresolved statutory and liability questions increased the litigation risk for both sides. The settlement closes the class claims without requiring Comcast or Citrix to admit wrongdoing, while establishing a $117.5 mn fund for affected Comcast customers.