Around December 18, 2023, millions of Comcast Xfinity customers got an email that probably didn’t stand out. It was another breach notification from another company, which said in a quiet way that someone had stolen personal information. Simple to ignore. It’s easier to forget. But the effects of that cybersecurity incident in October 2023 are still being felt, and there is currently a $117.5 million settlement fund that most eligible customers may never be able to get money from.
In the usual grim way that these things tend to be, the breach itself wasn’t too hard. A third party got into customer data without permission. Comcast, on the other hand, says it did nothing wrong. This is standard legal language that is expected and almost feels like a ritual at this point. But there has to be pressure for a court-supervised settlement to happen, and $117.5 million is not a rounding error. It is said that more than 35 million customers were affected, making this one of the biggest settlements for a data breach in recent memory.
The company Kroll Settlement Administration LLC is in charge of claims. It’s not as important as it seems that little thing. Con artists have been following this settlement like they follow any big payout, and the Kroll Settlement Comcast process follows a very clear, observable pattern. Communications that are legal will only link to ComcastBreachSettlement.com and mention the case name, Hasson v. Comcast Cable Communications LLC. If you get an email about this settlement that tells you to go somewhere else, demands money up front, or tells you to act right away, you should think twice before clicking anything.
There are a few different types of things that settlement class members can actually get. Anyone who is eligible and was told about the breach on or around December 18, 2023, will automatically get three years of identity protection services thru CyEx Financial Shield Complete. These services include credit monitoring, dark web scanning, and up to $1 million in identity theft insurance. That part doesn’t need any work. When it comes to cash, things are different. A claim form must be turned in by September 14, 2026, in order to get reimbursed for documented out-of-pocket losses or paid $30 an hour, up to five hours, for the time spent dealing with the aftermath of the breach. There is also a cash payment option for people who can’t prove they lost specific items.

It’s still not clear how much each payout will be because the final amount depends on how many claims are made. It’s not easy to do the math. But the process is. Visit the official site for the settlement. Enter the Class Member ID that was given to you in the first notice. Keep any proof you can, like receipts, bank records, or even a written record of the time you spent on tasks related to the breach. Send it in before the due date. It won’t make anyone feel better about having their personal information shared, but it is real money that goes with a real legal process.
Based on how these settlements usually go, it seems like most of the people who are eligible to file a claim will not do anything. It’s not that they don’t know, but because life is busy and deadlines seem far away until they aren’t. It sounds like September 14, 2026 is a long time away. It won’t until the summer of next year. Making a calendar note no longer costs anything.
The deadline for people who want to completely reject the settlement and keep their right to sue on their own has already passed. July 1, 2026 was the last day to both reject the settlement and file a formal objection. This means that you can either file a claim or do nothing and just get the monitoring services. It’s not hard to make a decision, but the bigger issues of data security and corporate responsibility are still, as usual, harder to answer.

