U

Visitor

 • 

9 Messages

Friday, February 11th, 2022 8:53 PM

Closed

Scam email to my Comcast email addresses

I use unique email addresses in many places including Xfinity. In other words, I give Xfinity email addresses that nobody else has or even knows about. It is not a coincidence I have received multiple scam (not spam) emails this week to two different email addresses that only Xfinity knows about. One was to my current email address and the other was to an old email address used years ago for my father. One email was telling me I have renewed Norton Life lock which I have never used and the other seemed like it was coming from Amazon telling me a $1,400 iPhone I ordered was on its way. Of course, both want me to call a phone number if there was any mistakes or problems so they can trick me into giving them my credit card number.

I see two possibilities. One is that Xfinity is releasing our email addresses to scammers which I doubt and the other is Xfinity has been hacked recently or this is from an older breach.

Either way it is not cool and I hope everybody gets warned. There are not many people like me who realizes where a particular scam email obtained my email address.

P.S. there was no real place to report something like this. No way I'm going to call and speak to an [Edited: "Inflammatory"] It doesn't know what I'm talking about and it won't matter anyway.

Official Employee

 • 

1.3K Messages

3 years ago

Hi @user_a84c61, any concerns regarding the security of our e-mail service can be addressed by our Customer Security Assurance team (CSA). All you would need to do is call 1-800-XFINITY and request to be transferred to our Customer Security Assurance team (CSA). They should be able to address any concerns you may have in regards to the security of the account. 

Visitor

 • 

9 Messages

@XfinityDemitrius​ Received another email from my Comcast email address. One that I gave to Comcast and Comcast only and use nowhere else and gave to no one else.

* It contains my full name.

* It's obviously a scam .

* It says we have received your order but I did not place an order.

* It says my order has been auto renewed which doesn't make sense if I placed an order.

* Says my bank account has been auto debited but I never use my bank account to pay for things.

 

Was there a time Comcast was preached and gave free McAfee credit monitoring? If so one of your partners is a possible source of the email stealing.

Part of the email...

 

Dear (my name)

We have received your order.
We are much obliged to inform you that your order has been auto-renewed. We have charged you an amount of $298.99 for McAfee® Total Protection.
You can call our customer service team for a refund- +[Edited: "Personal Information"]
-----------------
Notes:
1. Your account has been auto-debited and the charge will appear on your bank account in the next 24 hours.
2. Please retain the copy of Invoice as the proof of your service for 1 year. If you have any questions or queries about your order then see the help document!

Steve [Edited: "Personal Information"]
Billing Team
+1-[Edited: "Personal Information"]

(edited)

Official Employee

 • 

1.7K Messages

Thank you so much for getting back to us about the Email concern, @user_a84c61! We have a dedicated team that handles Emails like this and you can report the Email here so they can investigate it further. 

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Visitor

 • 

9 Messages

3 years ago

Happened to me and a couple others that I know about. Xfinity shut it all down and denies everything. They also closed my thread posting "Data Leak". Someone even replied on it and gave the similar description (@user_9e6fd9). Sounds really shady on their part.

Below is what originally posted. Hopefully my post doesn't disappear again... Xfinity. We should not be silenced or blown off. We should be taken seriously.

"What is Xfinity doing about the latest data leak? So far, I know my email address and name has been compromised from xfinity but have not received an email from xfinity regarding the incident. I am getting dozens of spam emails. I have an email account set up specifically for xfinity so there is no confusion. We deserve to know what other information has been compromised and what you are doing about it."

https://forums.xfinity.com/conversations/customer-service/data-leak/6201e0c0e5fd17166fe4c47e 

(edited)

Official Employee

 • 

1.5K Messages

Hi @iklopez501 thank you for your feedback. Any concerns regarding the security of our e-mail service can be addressed by our Customer Security Assurance team (CSA). All you would need to do is call 1-800-XFINITY and request to be transferred to our Customer Security Assurance team (CSA). They should be able to address any concerns you may have in regards to the security of the account. 
I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Visitor

 • 

9 Messages

@XfinityPeterH

I called the Comcast Security Assurance Team and they assured me my account was safe because I have MFA when I log in. While that's great, I don't think my information was compromised there. They also had me send them copies of the emails. I appreciate their help but unless someone is really looking into this, I believe this will just snowball from here.

I suspected this is something larger. It might not even be on Comcast's radar yet. All I know is that it is not a coincidence and I bet if more people checked, they would see that they are receiving targeted spam through the email account used for their Comcast account.

Official Employee

 • 

1.5K Messages

@iklopez501
Thanks for the update and letting us know your experience. Have you followed up with the CSA team, did they provide you with a ticket number, did they educate you on marking these emails as spam to report them? 

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Visitor

 • 

9 Messages

@iklopez501​ There is definitely something going on and Xfinity won't admit it or perhaps doesn't even realize it. My favorite is when I call to report something like this, do not get the promised call back and call again in the future to be told nobody (including me) has ever notified them of this before.

This is not the first time I've reported this type of thing to various companies both large and small and none of them  pay any attention. Most people use one email address and don't know where scammers get their address. Those few of us who use unique addresses given to one and only one company do know and we are the first line of defense and nice enough to spend time notifying these companies who deny or don't care. 

They also can't explain how information in their possession only is being used by scammers. Again, in my case, it's two different addresses both used by scammers for the first time this week.

I didn't leak these two addresses and none of my other many unique addresses have been targeted so anyone who can think logically can put two and two together. It's not a coincidence.

Visitor

 • 

1 Message

3 years ago

A bit confusing but: I got a message from google (I do have a Google account but don't use my Gmail address) saying that an email from my Comcast account could not be delivered because it was sent to a non-existent Gmail address, which they provided. It's true I do not have that Gmail address, but I have no sent messages or attempts from my Comcast account. And I did not get any unfamiliar authorization requests. 🤔

(edited)

Problem Solver

 • 

1.4K Messages

@user_414f92 Hello, and thank you for taking the time to reach out. I am sorry to hear you got a confusing email and I can understand how this would be concerning. Have you also reached out to our CSA team for further guidance like we have advised others to do? 

I no longer work for Comcast.

Visitor

 • 

9 Messages

3 years ago

Not saying this is related but definitely an interesting coincidence if not. I just got an alert from my personal information monitoring service that my social security number was found on a Dark Web site. I immediately placed a fraud alert to the credit bureaus as a precaution. Fellow consumers beware.

Visitor

 • 

9 Messages

3 years ago

Now I received a call from an individual posing as a comcast rep (mind you the Caller ID was spoofed and said "Comcast"). This person advised they were calling because my router was showing as the firewall being down. So I restarted my router, no harm in that. Then he said no it still shows the firewall is down. I need you to log into your router please go to this website... and that's when I said NO. I dont think you are Comcast I will call in myself. He said he was going to terminate my service because I cannot operate without a firewall per the terms and conditions. I hung up and called Comcsst. They indeed confirmed there was no agent that called me much less is there any issue with my internet. They immediately transfered me to the CSA team which then gave me a number to call the "level 2" team. 

THIS IS GETTING WAY OUT OF HAND. REACT COMCAST REACT. 

(edited)

Official Employee

 • 

1.2K Messages

Hello @iklopez501 ! Thank you so much for keeping us up-to-dat on everything going on! It's wonderful that you've already touched basis with our Comcast Security Assurance Team, and these experts are the best folks to talk with about this situation. We do take incidents like this very seriously,  and will do all we can to ensure that this is resolved and taken care of for you. For future refence the CSA Team can be reached using the info below. 

 

 

https://internetsecurity.xfinity.com/help/report-abuse

 

 

  • Business Hours: 6:00am - 2:00am EST, 7 days a week
  • Contact: 1-888-565-4329

 

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Visitor

 • 

9 Messages

@iklopez501​ After the things Comcast has done to me I know the abysmal mess they are but I always try to be reasonable, rational and fair. In this case, I don't see Comcast did anything wrong. Scammers spoof their caller ID and randomly call people. Sounds like that's what happened to you. Since you didn't say they had information only Comcast could know, is seems something like this is out of Comcast's control and they didn't cause it and there is nothing they could do about it. In my (and other's cases) the scammers had information given ONLY to Comcast so that information would have most likely come from or have been taken from Comcast with or without their knowledge.

It's good you were aware enough to be suspicious and question things. Too bad more people aren't which is why scammers continue.

Visitor

 • 

9 Messages

3 years ago

That's true but for me it's too much coincidence. A spoofed call from Comcast precisely when I feel as that exact company has suffered a data leak. One where apparently my email, name, and now phone number was compromised. That's all. It's too much coincidence for me. 

I submitted reports to the FCC as advised by CSA. Hopefully, this ends soon. I am seeing a lot of posts with if not similar but still data related concerns.

Visitor

 • 

9 Messages

3 years ago

More information and just venting because nothing will be done.  First, about the blocked out part of my original post where they replaced a word with [Edited: "Inflammatory"] . It was a mild word like "pinhead"  ( p i n h e a d) or something not what I think is inflammatory. Just accurate. On top of what they have done, it's beyond frustrating to tell it to their people and receive vacant stares in return followed by apologies. LOTS of apologies. Comcast Xfinity must pay their people based on the number of times they say they are sorry. Not that it fixes anything. I feel sorry for the innocent workers who have to take the brunt of understandably irate callers.  

OK. I'm still getting Norton scam emails where I have to call to reverse a "purchase" to the email address I gave Comcast and ONLY Comcast. I updated my email address in my profile over a month ago. Interesting that I'm new getting some (valid) email to the new address and recently received what appears valid to the OLD address. In other words, they must store email addresses in different places and updating one doesn't update them all which is a big data validation\storage No-No. 

Someone IS doing nefarious things with email addresses they obtained from Comcast. There is no other way to explain what i and others have experienced. There is no way to know if they care or even know but they certainly are not admitting it. Too bad they won't be held liable for all the people scammed as a result. Or might it someday happen? One can only dream.

Visitor

 • 

9 Messages

@user_a84c61​ 

I feel your pain. I still receieve these emails and I 100% KNOW something is up and it's originating with Xfinity. Not only do I only use this email address for my xfinity account but for whatever reason Xfinity dropped the last letter of my first name and ALL the spam emails that I receieve, address me by that name. It's such a no brainer for me. Name and email were compromised by xfinity. 

Official Employee

 • 

923 Messages

Hi, @iklopez501. Have you contacted our CSA (Customer security assurance) team yet? If you think your account was compromised, that's the first team I would recommend. 

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

New Poster

 • 

2 Messages

2 years ago

Same here. I have an comcast.net email I only use to login and pay my bill. I don't use for anything else. Everytime I log in to pay my comcast bill there are at least 50 spam emails.

forum icon

New to the Community?

Start Here