Comcast moved toward resolving litigation tied to its 2023 Citrix Bleed-linked breach, after a federal judge in Pennsylvania granted preliminary approval to a $117.5M settlement covering two dozen class actions. The incident was reported as potentially affecting ~30M current and former customers; proposed relief includes three years of credit/identity monitoring plus either reimbursement of documented losses (up to $10,000) or a $50 cash option, while Comcast continues to deny liability despite not opposing preliminary approval.
Separately, South Korea’s SK Telecom rejected a government-affiliated consumer agency’s proposed compensation framework for a personal data leak, declining a plan that would pay 100,000 won (~$69.40) per affected petitioner and potentially scale to a much larger total cost; the rejection leaves claimants to pursue individual civil suits. In a different telecom-related development not tied to a breach, the FCC opened a dedicated intake channel to collect customer reports as it investigates the January 14 Verizon outage that disrupted calling/texting for roughly 10 hours, including impacts to 911 access; Verizon attributed the disruption to a software issue and offered customer credits.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
A federal judge in the Eastern District of Pennsylvania granted preliminary approval to a proposed $117.5 million settlement resolving 24 class action lawsuits over Comcast's 2023 breach. The deal would provide affected customers with three years of financial monitoring and identity-theft protection, plus either up to $10,000 in expense reimbursement or a $50 cash payment.
SK Telecom rejected a settlement proposal from a government-affiliated consumer agency that would have paid 100,000 won per affected user. The company said the plan could cost about 2.3 trillion won, and the rejection ended the settlement process without agreement, leaving petitioners to pursue civil lawsuits.
After accepting responsibility for the breach, SK Telecom filed suit seeking to overturn a regulator-imposed penalty of about $91 million. The legal challenge represented the company's pushback against sanctions tied to the incident.
SK Telecom publicly accepted full responsibility for a personal data leak affecting its users. The disclosure marked the company's formal acknowledgment of the incident and its consequences.
In 2023, Comcast experienced a data breach tied to the Citrix Bleed vulnerability that exposed data belonging to current and former customers. Reporting later indicated the incident potentially affected more than 30 million people, with one related notification listing 35,879,455 consumers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.