Comcast Used '0000' as Default PIN for Xfinity Mobile Customers, Leaving Them Vulnerable to Hacking

Comcast's Xfinity Mobile service used "0000" as a default PIN for all of its mobile customers, which left them vulnerable to hacking attempts, identity theft, and more.

Comcast's decision to use simple default PINs for all of its customers came to light in a "Help Desk" article from The Washington Post included one Comcast customer's tech horror story.

xfinitymobilelogo
Larry Whitted, an Xfinity Customer in California, had someone hijack his phone number, port it to a new account on another network, and steal his identity to commit fraud.

The thief put Samsung Pay on a new phone with Whitted's phone number and credit card then bought himself a computer at the Apple Store.

This was possible because Comcast does not ask its customers to create a PIN to secure their accounts to prevent them from being transferred to another carrier. Instead, Comcast uses the default 0000 code. From Comcast's support document:

We don't require you to create an account PIN, so you don't need to provide that information to your new carrier.

Taking control of a person's telephone number is a popular way to obtain logins for email, social media accounts, bank accounts, and more. Any site that uses a phone number as a way of authenticating data can be accessed when someone has your phone number.

Charismatic hackers who use social engineering techniques can often get access to phone numbers from customer service representatives who don't know any better, but many carriers have implemented PIN codes to make it more difficult. Not Comcast.

This has led to other Xfinity Mobile customers having their phone numbers hijacked as well, and with phone numbers used for so much, hackers can access a lot of a person's data.

Comcast says that it has since implemented new measures to make it harder to steal phone numbers and that it is "working aggressively" to create a PIN-based solution, something that common sense dictates should have been available from the time the service launched.

Comcast says that a "very small number" of its customers have been impacted by this issue, and rightly admits that having even "one customer impacted" is "one too many." Comcast claims that customers who were affected perhaps used passwords leaked in other data breaches

Tag: Comcast

Popular Stories

iphone 16 display

iPhone 17's Scratch Resistant Anti-Reflective Display Coating Canceled

Monday April 28, 2025 12:48 pm PDT by
Apple may have canceled the super scratch resistant anti-reflective display coating that it planned to use for the iPhone 17 Pro models, according to a source with reliable information that spoke to MacRumors. Last spring, Weibo leaker Instant Digital suggested Apple was working on a new anti-reflective display layer that was more scratch resistant than the Ceramic Shield. We haven't heard...
iPhone 17 Air Pastel Feature

iPhone 17 Reaches Key Milestone Ahead of Mass Production

Monday April 28, 2025 8:44 am PDT by
Apple has completed Engineering Validation Testing (EVT) for at least one iPhone 17 model, according to a paywalled preview of an upcoming DigiTimes report. iPhone 17 Air mockup based on rumored design The EVT stage involves Apple testing iPhone 17 prototypes to ensure the hardware works as expected. There are still DVT (Design Validation Test) and PVT (Production Validation Test) stages to...
Beyond iPhone 13 Better Blue

20th Anniversary iPhone Likely to Be Made in China Due to 'Extraordinarily Complex' Design

Monday April 28, 2025 4:29 am PDT by
Apple will likely manufacture its 20th anniversary iPhone models in China, despite broader efforts to shift production to India, according to Bloomberg's Mark Gurman. In 2027, Apple is planning a "major shake-up" for the iPhone lineup to mark two decades since the original model launched. Gurman's previous reporting indicates the company will introduce a foldable iPhone alongside a "bold"...
iphone 17 air iphone 16 pro

iPhone 17 Air USB-C Port May Have This Unusual Design Quirk

Wednesday April 30, 2025 3:59 am PDT by
Apple is preparing to launch a dramatically thinner iPhone this September, and if recent leaks are anything to go by, the so-called iPhone 17 Air could boast one of the most radical design shifts in recent years. iPhone 17 Air dummy model alongside iPhone 16 Pro (credit: AppleTrack) At just 5.5mm thick (excluding a slightly raised camera bump), the 6.6-inch iPhone 17 Air is expected to become ...
apple watch ultra yellow

What's Next for the Apple Watch Ultra 3 and Apple Watch SE 3

Friday April 25, 2025 2:44 pm PDT by
This week marks the 10th anniversary of the Apple Watch, which launched on April 24, 2015. Yesterday, we recapped features rumored for the Apple Watch Series 11, but since 2015, the Apple Watch has also branched out into the Apple Watch Ultra and the Apple Watch SE, so we thought we'd take a look at what's next for those product lines, too. 2025 Apple Watch Ultra 3 Apple didn't update the...
iPhone 17 Pro Blue Feature Tighter Crop

iPhone 17 Pro Launching Later This Year With These 13 New Features

Wednesday April 23, 2025 8:31 am PDT by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. Below, we recap key changes rumored for the iPhone 17 Pro models as of April 2025: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro models have a titanium frame, and the iPhone ...
iPhone 17 Pro on Desk Feature

All iPhone 17 Models Again Rumored to Feature 12GB of RAM

Tuesday April 29, 2025 3:36 am PDT by
All upcoming iPhone 17 models will come equipped with 12GB of RAM to support Apple Intelligence, according to the Weibo-based leaker Digital Chat Station. The claim from the Chinese leaker, who has sources within Apple's supply chain, comes a few days after industry analyst Ming-Chi Kuo said that the iPhone 17 Air, iPhone 17 Pro, and iPhone 17 Pro Max will all be equipped with 12GB of RAM. ...
AirPods Pro 3 Mock Feature

AirPods Pro 3 Just Months Away – Here's What We Know

Tuesday April 29, 2025 1:30 am PDT by
Despite being more than two years old, Apple's AirPods Pro 2 still dominate the premium wireless‑earbud space, thanks to a potent mix of top‑tier audio, class‑leading noise cancellation, and Apple's habit of delivering major new features through software updates. With AirPods Pro 3 widely expected to arrive in 2025, prospective buyers now face a familiar dilemma: snap up the proven...

Top Rated Comments

npmacuser5 Avatar
81 months ago
Where exactly did we go wrong to get from there to here? Even into the early 2000s we operated PCs without user logins and passwords. The world is hardly recognisable now. What a sad story about humanity.
Going on for a longtime. 1970’s, rarely locked the doors in my neighborhood. Nothing ever went missing. Today deadbolts and security plus camera systems the normal.

The decline continues. A truly sad story.
Score: 8 Votes (Like | Disagree)
Cyberpower678 Avatar
81 months ago
Comcast: Security is for sissies. You don't really need a password, 2FA, or device security codes, bank PINs, thumbprints, or Face ID. We live in an honest world. Right? RIGHT?
Score: 6 Votes (Like | Disagree)
macduke Avatar
81 months ago
Classic Comcast. I would never expect anything better.
Score: 5 Votes (Like | Disagree)
notabadname Avatar
81 months ago
Going on for a longtime. 1970’s, rarely locked the doors in my neighborhood. Nothing ever went missing. Today deadbolts and security plus camera systems the normal.

The decline continues. A truly sad story.
Simply not true. Crime has been on the decline since the 90’s. Depending on crime type, its generally no different percapita than it was in the 70’s and acually, lower for burglury and vehicle threat. Your memory of the 70’s predated 24 hour news cycles. So we are simply more aware of crime. When you had only an hour of news in the 70’s, Walter Cronkite had to stick to the big stories.

The spreading of incorrect information continues. A truer sad story.

Stats ('https://en.m.wikipedia.org/wiki/Crime_in_the_United_States#/media/File%3AProperty_Crime_Rates_in_the_United_States.svg')
Score: 4 Votes (Like | Disagree)
Apple_Robert Avatar
81 months ago
I am not one to use the "sue" word very often. In this case, I believe Comcast earned it.
Score: 4 Votes (Like | Disagree)
StellarVixen Avatar
81 months ago
They should change it to "password" or 1234
Score: 4 Votes (Like | Disagree)