Comcast Used '0000' as Default PIN for Xfinity Mobile Customers, Leaving Them Vulnerable to Hacking

Comcast's Xfinity Mobile service used "0000" as a default PIN for all of its mobile customers, which left them vulnerable to hacking attempts, identity theft, and more.

Comcast's decision to use simple default PINs for all of its customers came to light in a "Help Desk" article from The Washington Post included one Comcast customer's tech horror story.

xfinitymobilelogo
Larry Whitted, an Xfinity Customer in California, had someone hijack his phone number, port it to a new account on another network, and steal his identity to commit fraud.

The thief put Samsung Pay on a new phone with Whitted's phone number and credit card then bought himself a computer at the Apple Store.

This was possible because Comcast does not ask its customers to create a PIN to secure their accounts to prevent them from being transferred to another carrier. Instead, Comcast uses the default 0000 code. From Comcast's support document:

We don't require you to create an account PIN, so you don't need to provide that information to your new carrier.

Taking control of a person's telephone number is a popular way to obtain logins for email, social media accounts, bank accounts, and more. Any site that uses a phone number as a way of authenticating data can be accessed when someone has your phone number.

Charismatic hackers who use social engineering techniques can often get access to phone numbers from customer service representatives who don't know any better, but many carriers have implemented PIN codes to make it more difficult. Not Comcast.

This has led to other Xfinity Mobile customers having their phone numbers hijacked as well, and with phone numbers used for so much, hackers can access a lot of a person's data.

Comcast says that it has since implemented new measures to make it harder to steal phone numbers and that it is "working aggressively" to create a PIN-based solution, something that common sense dictates should have been available from the time the service launched.

Comcast says that a "very small number" of its customers have been impacted by this issue, and rightly admits that having even "one customer impacted" is "one too many." Comcast claims that customers who were affected perhaps used passwords leaked in other data breaches

Tag: Comcast

Top Rated Comments

npmacuser5 Avatar
53 months ago
Where exactly did we go wrong to get from there to here? Even into the early 2000s we operated PCs without user logins and passwords. The world is hardly recognisable now. What a sad story about humanity.
Going on for a longtime. 1970’s, rarely locked the doors in my neighborhood. Nothing ever went missing. Today deadbolts and security plus camera systems the normal.

The decline continues. A truly sad story.
Score: 8 Votes (Like | Disagree)
Cyberpower678 Avatar
53 months ago
Comcast: Security is for sissies. You don't really need a password, 2FA, or device security codes, bank PINs, thumbprints, or Face ID. We live in an honest world. Right? RIGHT?
Score: 6 Votes (Like | Disagree)
macduke Avatar
53 months ago
Classic Comcast. I would never expect anything better.
Score: 5 Votes (Like | Disagree)
notabadname Avatar
53 months ago
Going on for a longtime. 1970’s, rarely locked the doors in my neighborhood. Nothing ever went missing. Today deadbolts and security plus camera systems the normal.

The decline continues. A truly sad story.
Simply not true. Crime has been on the decline since the 90’s. Depending on crime type, its generally no different percapita than it was in the 70’s and acually, lower for burglury and vehicle threat. Your memory of the 70’s predated 24 hour news cycles. So we are simply more aware of crime. When you had only an hour of news in the 70’s, Walter Cronkite had to stick to the big stories.

The spreading of incorrect information continues. A truer sad story.

Stats ('https://en.m.wikipedia.org/wiki/Crime_in_the_United_States#/media/File%3AProperty_Crime_Rates_in_the_United_States.svg')
Score: 4 Votes (Like | Disagree)
Apple_Robert Avatar
53 months ago
I am not one to use the "sue" word very often. In this case, I believe Comcast earned it.
Score: 4 Votes (Like | Disagree)
StellarVixen Avatar
53 months ago
They should change it to "password" or 1234
Score: 4 Votes (Like | Disagree)

Popular Stories

iPhone 15 Pro Buttons CAD Leak

iPhone 15 Pro Leak Reveals Unified Volume Button and Mute Button

Monday March 20, 2023 8:33 am PDT by
As previously rumored, the next-generation iPhone 15 Pro and iPhone 15 Pro Max will feature a unified volume button and a mute button, according to leaked CAD images shared in a video on the Chinese version of TikTok and posted to Twitter by ShrimpApplePro. Instead of separate buttons for volume up and volume down, the iPhone 15 Pro models are expected to have a single elongated button for...
original iphone auction

Factory-Sealed Original iPhone Sells for $55,000 at Auction

Friday March 17, 2023 1:08 pm PDT by
A first-generation iPhone still sealed inside its box sold for $54,904 at auction, which is more than $54,000 over the original $599 price tag of the device when it was released in 2007. The original iPhone was put up for sale by RR Auction on behalf of a former Apple employee who purchased it back when it first came out. Back in February, an original, sealed iPhone sold for over $63,000,...
iPhone 12 Pro vs iPhone 15 Pro Feature

iPhone 12 Pro vs. 15 Pro: New Features to Expect if You've Waited to Upgrade

Friday March 17, 2023 10:29 am PDT by
While year-over-year iPhone upgrades are not always groundbreaking, new features can begin to stack up over multiple generations. For example, the iPhone 15 Pro will be a notable upgrade for those who still have a three-year-old iPhone 12 Pro. If you are still using an iPhone 12 Pro and are considering upgrading to the iPhone 15 Pro when it launches later this year, we have put together a...
top stories 18mar2023

Top Stories: iPhone 15 Pro Pricing, New iOS 16.4 Beta, Siri vs. ChatGPT, and More

Saturday March 18, 2023 6:00 am PDT by
Apple's high-end iPhone models have started at $999 in the U.S. since they first launched back in 2017 with the iPhone X, but could this finally be the year that starting price sees an increase? This week also saw some more rumors about Apple's upcoming headset and the company's explorations in the booming AI industry as well as the release of a new round of beta updates, so read on for all...
iPhone 15 Pro Mock Feature Buttonless

iPhone 15 Pro Max to 'Break Record' for Thinnest Bezels on a Smartphone

Friday March 17, 2023 2:59 am PDT by
The iPhone 15 Pro Max will have the thinnest bezels of any smartphone, beating the record currently held by the Xiaomi 13. That's according to the leaker known as "Ice Universe," who has divulged accurate information about Apple's plans in the past. Both iPhone 15 Pro models are expected to have thinner, curved bezels compared to the iPhone 14 Pro, potentially resulting in an Apple...
iphone 14 pro max deep purple feature purple

iPhone 15 Pro Launching This Year With These 11 New Features

Monday March 13, 2023 6:47 am PDT by
While the iPhone 15 lineup is around six months away, there have already been plenty of rumors about the devices. Many new features and changes are expected for the iPhone 15 Pro models in particular, including a titanium frame and more. Below, we have recapped 11 features rumored for iPhone 15 Pro models that are not expected to be available on the standard iPhone 15 and iPhone 15 Plus:A17...
iOS 16

iOS 16.4 for iPhone Nearing Launch With These 5 New Features

Monday March 20, 2023 11:50 am PDT by
Apple continues to test iOS 16.4, which includes a handful of new features and changes for the iPhone. Below, we have recapped five new features coming with the software update, including new emoji, push notifications from websites, and more. Apple says iOS 16.4 will be available in the spring, which begins today. In his newsletter this weekend, Bloomberg's Mark Gurman said the update should ...