The Federal Communications Commission has fined Comcast $1.5 million following a data breach at Financial Business and Consumer Solutions (FBCS), a former debt collection vendor, that exposed sensitive information from 237,703 current and former Comcast customers. The breach occurred in early 2024, long after Comcast stopped placing accounts with the agency, but still involved customer data the vendor retained.
The Commission found the breach compromised personally identifiable information tied to Comcast’s cable subscribers, triggering obligations under Section 631 of the Cable Act. Comcast agreed to the voluntary payment and will implement a new compliance plan that strengthens vendor oversight and data-security practices.
What Happened
- A ransomware attack hit FBCS between February 14 and 26, 2024.
- The breach exposed names, addresses, dates of birth, Social Security numbers, account numbers and internal IDs for Comcast customers across internet, TV, streaming, home security and VoIP services.
- FBCS filed for bankruptcy before disclosing the breach, leaving Comcast to notify state authorities and affected customers.
- The breach also impacted other companies, including Truist Bank.
Settlement Details
Under the settlement, Comcast must:
- Pay a $1.5 million voluntary contribution to the U.S. Treasury.
- Implement an enhanced Compliance Plan covering:
- Employee training on subscriber-privacy requirements
- Strengthened data-protection protocols
- Incident reporting procedures
- Establish a Vendor Management Program that includes:
- Comprehensive data-tracking of information shared with vendors
- Biennial risk assessments
- Data-retention and deletion requirements
- Ongoing vendor security monitoring and breach-response obligations DA-25-973A1
Comcast emphasized that its own systems were not compromised and stated it “was not responsible for and has not conceded any wrongdoing.” It also noted that vendors like FBCS are contractually required to follow its security requirements.
.




