Skip to Content

Comcast Xfinity accounts hacked by credential stuffing attacks bypassed 2FA security

Updated on 2022-12-29: Comcast Xfinity account hacks

Several Comcast Xfinity customers said they had their accounts hacked. The accounts were then used to reset passwords and bypass 2FA accounts on cryptocurrency portals like Gemini and Coinbase.

Overview

Comcast Xfinity accounts have been hacked in widespread credential stuffing attacks that bypassed the 2FA security. The compromised accounts enabled attackers to reset passwords for other sites such as Coinbase and Gemini.

Xfinity verification email in a disposable Yopmail inbox

Read more:

  • Xfinity Community Forum > Email hacked, password changed and 2 step turned off
  • r/Comcast_Xfinity > Hackers bypassed 2FA, possible CSR’s social engineered
  • r/Comcast_Xfinity > Just how many xfinity accounts were hacked yesterday