Judge Approves $117.5 Million Settlement in ‘Complex’ Comcast Data Breach Case

August 25, 2026 by

A federal judge has approved a $117.5 million data breach settlement against Comcast Cable Communications.

The agreement represents one of the largest data breach settlement amounts and, with 31.7 million potential members, one of the largest classes in a data breach case.

The case also represents one of the more complex data breach cases to date, according to Judge John Younge of the U.S. District Court for the Eastern District of Pennsylvania who approved the settlement.

Comcast customers complained about a data breach that occurred between October 16 and October 19, 2023, when cybercriminals exploited the “Citrix Bleed” vulnerability in the Citrix NetScaler appliance that Comcast used to manage remote access by customers and contractors.

Comcast did not notify affected customers until December 18, 2023 — roughly two months after the intrusion.

The plaintiffs claimed that Comcast failed to timely install the patch Citrix had made available; that Citrix failed to adequately test and monitor its NetScaler product; and that both companies’ conduct exposed class members to actual and attempted identity theft, fraud, and a substantial risk of further injury.

According to the complaint, the breach exposed personal information including names, contact information, dates of birth, the last four digits of Social Security numbers, secret questions and answers, and, for some class members, full Social Security numbers and driver’s license numbers.

The plaintiffs asserted 23 causes of action, including state common law claims, state statutory claims, as well as claims under the federal Cable Communications Policy Act, which the class lawyers indicated was the first time this federal law had been invoked for a cable company data breach.

Comcast and Citrix denied all allegations of wrongdoing.

The settlement was ultimately reached through five separate mediation sessions. The court issued a preliminary approval in January.

The agreement releases both Comcast and Citrix from all class claims related to the data breach, but the $117.5 million common fund is being funded by Comcast.

Under the settlement, class members may submit claims up to $10,000 per person for reimbursement of out-of-pocket losses and lost time. As an alternative to itemized claims, class members may claim a $50 cash payment. All members get a free subscription to a credit monitoring service.

The court approved an attorneys’ fee of $31.7 million, or 27% of the settlement fund. The court credited the lawyers with efficiently handling what was a complex case within two years.

In approving the fund and the attorneys’ fee, Judge Younge noted that data breach litigation “is inherently complex” given “the difficulty of proving class-wide damages” and “issues about the duty of care” that a defendant owes in connection with personal information. This litigation was more complex than most, the judge added.

Part of the complexity was due to the claims under the federal Cable Act—a statute that, to class counsel’s knowledge, had never been applied to a data breach by a cable operator. Whether the compromised information constitutes “personally identifiable information” under the Cable Act, and whether such information is sufficiently sensitive to satisfy the statute, were unresolved threshold questions. The plaintiffs’ claim against Citrix turned on whether a cybersecurity vendor owes a duty of care to end-users of its customers—people with whom Citrix had no direct relationship and whose data Citrix never directly handled. No court in the Third Circuit had resolved that question, according to the judge.

The judge said that the factual issues were also demanding. The difficult and contested facts requiring expert testimony included whether the last four digits of Social Security numbers are sufficiently sensitive, whether Comcast’s use of a single iteration of a secure hash algorithm was “innocuous or dangerously susceptible to cracking,” and whether the plaintiffs’ data appeared on the dark web.

The case spanned approximately two years from first-filed action to global resolution. The judge said this factor weighed in favor of the 27% legal fee.