Comcast agreed to pay $117.5M to settle a class action tied to a large-scale breach disclosed in late 2023 that potentially affected 31M+ people. Comcast attributed the intrusion to CitrixBleed (Citrix NetScaler ADC/Gateway), a vulnerability that can enable session hijacking and credential theft; researchers warned stolen session tokens could remain valid even after patching, extending attacker access. The proposed settlement (preliminarily approved) provides reimbursement for documented losses (up to $10,000 per person) and compensation for time spent responding, while Comcast denies wrongdoing.
Separately, Google agreed to pay $135M to settle Android users’ claims that devices transmitted data to Google servers over cellular networks in the background without meaningful consent, with individual payouts capped (reported up to $100) and additional injunctive relief requiring clearer disclosures and express consent during setup. Two dermatology practices also reached settlements over cybersecurity incidents exposing patient data; one New Jersey practice reported unauthorized network access spanning Dec 2023–Mar 2024 and exposure of PHI/PII (including SSNs and treatment/insurance data) affecting 373,630 individuals, offering cash benefits plus credit monitoring/identity protection while denying liability.

See attribution, scope, and your downstream exposure.
11 events from the most recent confirmed update back to the earliest known activity.
Comcast agreed to pay $117.5 million to settle class action claims over its 2023 data breach, and the settlement received preliminary court approval. The proposed deal includes reimbursement for documented losses and compensation for time spent responding to the incident.
Google agreed to pay $135 million to settle a proposed class action over alleged Android background data harvesting, while denying wrongdoing. The deal also includes injunctive relief requiring updated disclosures, express consent during device setup, and changes to background data controls.
Affiliated Dermatologists & Dermatologic Surgeons and U.S. Dermatology Partners agreed to settle class action lawsuits tied to their respective cybersecurity incidents. The settlements provide credit monitoring, reimbursement for losses, and in the New Jersey case up to $1 million in aggregate cash payments, with claim deadlines and fairness hearings scheduled in early 2026.
Class action litigation over the Affiliated Dermatologists & Dermatologic Surgeons incident was consolidated in New Jersey state court before the proposed settlement was announced.
In June 2025, researchers disclosed an updated CitrixBleed exploit variant capable of targeting session tokens used beyond browser sessions, potentially enabling longer-lived access.
U.S. Dermatology Partners experienced a cyberattack in June 2024 involving data exfiltration that affected nearly 14,000 individuals.
The unauthorized access affecting Affiliated Dermatologists & Dermatologic Surgeons continued into early 2024 before ending, concluding the exposure window cited in later litigation.
In December 2023, Comcast publicly disclosed the breach, notifying more than 31 million individuals across the U.S. and its territories.
Affiliated Dermatologists & Dermatologic Surgeons reported unauthorized access to its network beginning in late 2023, starting an incident that ultimately affected hundreds of thousands of individuals.
Comcast discovered a data breach in October 2023 that was later attributed to exploitation of the CitrixBleed vulnerability in Citrix NetScaler ADC and Gateway appliances.
Plaintiffs alleged that beginning on November 12, 2017, Android system services transmitted information to Google servers over cellular networks in the background, including when devices were locked, consuming users' paid data without meaningful consent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourceteiss.co.uk
Open sourcetechrepublic.com
Open sourcehelpnetsecurity.com
Open sourcehipaajournal.com
Open sourcecomcastbreachsettlement.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.