Comcast Used '0000' as Default PIN for Xfinity Mobile Customers, Leaving Them Vulnerable to Hacking

Comcast's Xfinity Mobile service used "0000" as a default PIN for all of its mobile customers, which left them vulnerable to hacking attempts, identity theft, and more.

Comcast's decision to use simple default PINs for all of its customers came to light in a "Help Desk" article from The Washington Post included one Comcast customer's tech horror story.

xfinitymobilelogo
Larry Whitted, an Xfinity Customer in California, had someone hijack his phone number, port it to a new account on another network, and steal his identity to commit fraud.

The thief put Samsung Pay on a new phone with Whitted's phone number and credit card then bought himself a computer at the Apple Store.

This was possible because Comcast does not ask its customers to create a PIN to secure their accounts to prevent them from being transferred to another carrier. Instead, Comcast uses the default 0000 code. From Comcast's support document:

We don't require you to create an account PIN, so you don't need to provide that information to your new carrier.

Taking control of a person's telephone number is a popular way to obtain logins for email, social media accounts, bank accounts, and more. Any site that uses a phone number as a way of authenticating data can be accessed when someone has your phone number.

Charismatic hackers who use social engineering techniques can often get access to phone numbers from customer service representatives who don't know any better, but many carriers have implemented PIN codes to make it more difficult. Not Comcast.

This has led to other Xfinity Mobile customers having their phone numbers hijacked as well, and with phone numbers used for so much, hackers can access a lot of a person's data.

Comcast says that it has since implemented new measures to make it harder to steal phone numbers and that it is "working aggressively" to create a PIN-based solution, something that common sense dictates should have been available from the time the service launched.

Comcast says that a "very small number" of its customers have been impacted by this issue, and rightly admits that having even "one customer impacted" is "one too many." Comcast claims that customers who were affected perhaps used passwords leaked in other data breaches

Tag: Comcast

Top Rated Comments

npmacuser5 Avatar
32 months ago
Where exactly did we go wrong to get from there to here? Even into the early 2000s we operated PCs without user logins and passwords. The world is hardly recognisable now. What a sad story about humanity.
Going on for a longtime. 1970’s, rarely locked the doors in my neighborhood. Nothing ever went missing. Today deadbolts and security plus camera systems the normal.

The decline continues. A truly sad story.
Score: 8 Votes (Like | Disagree)
Cyberpower678 Avatar
32 months ago
Comcast: Security is for sissies. You don't really need a password, 2FA, or device security codes, bank PINs, thumbprints, or Face ID. We live in an honest world. Right? RIGHT?
Score: 6 Votes (Like | Disagree)
macduke Avatar
32 months ago
Classic Comcast. I would never expect anything better.
Score: 5 Votes (Like | Disagree)
notabadname Avatar
32 months ago
Going on for a longtime. 1970’s, rarely locked the doors in my neighborhood. Nothing ever went missing. Today deadbolts and security plus camera systems the normal.

The decline continues. A truly sad story.
Simply not true. Crime has been on the decline since the 90’s. Depending on crime type, its generally no different percapita than it was in the 70’s and acually, lower for burglury and vehicle threat. Your memory of the 70’s predated 24 hour news cycles. So we are simply more aware of crime. When you had only an hour of news in the 70’s, Walter Cronkite had to stick to the big stories.

The spreading of incorrect information continues. A truer sad story.

Stats ('https://en.m.wikipedia.org/wiki/Crime_in_the_United_States#/media/File%3AProperty_Crime_Rates_in_the_United_States.svg')
Score: 4 Votes (Like | Disagree)
Apple_Robert Avatar
32 months ago
I am not one to use the "sue" word very often. In this case, I believe Comcast earned it.
Score: 4 Votes (Like | Disagree)
StellarVixen Avatar
32 months ago
They should change it to "password" or 1234
Score: 4 Votes (Like | Disagree)

Top Stories

REC ASA CODE2016 20160601 205816 2745

Elon Musk Reportedly Demanded to Become Apple CEO as Part of Potential Tesla Acquisition [Update: Musk Denies]

Friday July 30, 2021 9:04 am PDT by
Tesla CEO Elon Musk reportedly once demanded that he be made Apple CEO in a brief discussion of a potential acquisition with Apple's current CEO, Tim Cook. The claim comes in a new book titled "Power Play: Tesla, Elon Musk and the Bet of the Century," as reviewed by The Los Angeles Times. According to the book, during a 2016 phone call between Musk and Cook that touched on the possibility of ...
General Apps Messages

Android iMessage Competitor Puts Pressure on Apple

Friday July 30, 2021 3:15 am PDT by
Google and the three major U.S. carriers, including Verizon, AT&T, and T-Mobile, will all support a new communications protocol on Android smartphones starting in 2022, a move that puts pressure on Apple to adopt a new cross-platform messaging standard and may present a challenge to iMessage. Verizon recently announced that it is planning to adopt Messages by Google as its default messaging...
a15 chip

iPhone 13 and Redesigned MacBook Pro Chip Production Hit With Gas Contamination

Friday July 30, 2021 5:44 am PDT by
The most important TSMC factory that manufactures Apple's chips destined for next-generation iPhone and Mac models has been hit by a gas contamination, according to Nikkei Asia. The factory, known as "Fab 18," is TSMC's most advanced chipmaking facility. TSMC is Apple's sole chip supplier, making all of the processors used in every Apple device with a custom silicon chip. Industry...
Apple watch series 5 new case material made of titanium 091019

Titanium Apple Watch Series 6 Models Currently Widely Unavailable

Sunday August 1, 2021 6:21 am PDT by
Models of the Apple Watch Series 6 with titanium cases part of the "Apple Watch Edition" collection is currently widely unavailable for pick-up in several of Apple's retail stores in the United States and is unavailable entirely for delivery in major markets. Noted by Bloomberg's Mark Gurman in the latest edition of his "Power On" newsletter, titanium models of the Apple Watch Series 6,...
iPhone 13 Always On Feature

iPhone 13 to Bring Over a Major Feature From the Apple Watch

Wednesday July 28, 2021 2:21 am PDT by
Apple's upcoming iPhone 13 lineup will feature an always-on display akin to the Apple Watch Series 5 and Series 6, according to recent reports. In his weekly Power On newsletter, Bloomberg journalist Mark Gurman, who often reveals accurate insights into Apple's plans, said that the iPhone 13 may feature an Apple Watch-inspired always-on mode. The Apple Watch Series 5 and Apple Watch...
apple rtp land

Apple Preparing to Occupy 200,000 Square Feet of Temporary Space Ahead of New $1 Billion North Carolina Campus

Thursday July 29, 2021 9:14 am PDT by
Back in April, Apple announced a $430 billion investment over the next five years to create more than 20,000 new jobs as the company continues to expand. One significant piece of that plan is a new engineering and research center in North Carolina where Apple will be investing over $1 billion and hiring at least 3,000 employees. Assemblage of seven properties in Research Triangle Park owned by ...
telegram

Bumper Telegram Update Enables Video Calls With Up to 1,000 Viewers

Saturday July 31, 2021 12:13 am PDT by
Telegram Messenger has received a major update to its video capabilities, including support for video calls with up to 1,000 viewers. Group video calls in Telegram allow up to 30 users to stream video from both their camera and their screen, and now a maximum of 1,000 people can tune into the broadcast. Telegram says it intends to continue increasing this limit "until all humans on Earth...
app store blue banner

Elon Musk: Apple's App Store Fees Are a 'De Facto Global Tax on the Internet'

Friday July 30, 2021 10:04 am PDT by
Tesla CEO Elon Musk took to Twitter today to criticize Apple's App Store fees in a tweet that sides with Epic in the ongoing Epic v. Apple dispute. "Epic is right," wrote Musk, before going on to call Apple's App Store fees a "de facto global tax on the Internet." Musk earlier this week made veiled comments about App Store fees, but today's statement is a much more direct criticism....
FaceID iMac REREREREMIX

Top Stories: Face ID on Future Macs, Elon Musk Criticizes Apple, and More

Saturday July 31, 2021 6:00 am PDT by
This week saw an interesting range of Apple news and rumors, including a blockbuster earnings report, rumors about next year's "iPhone 14" and Face ID coming to Macs, and more. Subscribe to the MacRumors YouTube channel for more videos. Other popular topics included Apple's crackdown on leaks, changes in the latest round of betas for iOS 15, iPadOS 15, and macOS Monterey, and several stories...
duracell battery bitter coating

Apple Says Don't Buy AirTag Replacement Batteries With Bitter Coating

Wednesday July 28, 2021 11:08 am PDT by
Since AirTags were just released earlier this year and are expected to have a year-long battery life, it may be some time yet before AirTag users need a replacement battery, but when the time comes for a refresh, Apple is warning customers not to buy batteries with a bitter coating. AirTags use coin-shaped CR2032 batteries, which happen to be a size that's easy to swallow. Some battery...