Apps & Consumer
Crunchyroll confirms data breach affecting customer support records
Crunchyroll has confirmed a data breach involving customer service ticket information, with reports suggesting about eight million records may have been accessed by an unauthorized party.
Anime streaming service Crunchyroll has officially confirmed a data breach involving customer service ticket information. The confirmation follows online reports where a hacker claims unauthorized access to the platform’s systems. According to the hacker, the incident resulted in the download of about eight million support ticket records, which reportedly include roughly 6.8 million unique email addresses. The company has stated that it is actively investigating the claims, though it has not yet confirmed the hacker’s specific figures.
Separately, materials shared by International Cyber Digest, a cybersecurity-focused account, indicate that the attacker may have gained access to Crunchyroll’s Zendesk customer support software. The hacker claimed to have gained access on March 12 after compromising an Okta single sign-on account belonging to a support agent. The breach appears to stem from an employee at Telus Digital, an outsourcing partner that handles customer support for Crunchyroll. Screenshots shared by the cybersecurity account reportedly show internal communications and stolen support data. The hacker allegedly stole customer support ticket data until early 2025, at which point their access was revoked. Neither Telus Digital nor Crunchyroll has responded to follow-up questions regarding the connection to the outsourcing partner, and Telus Digital did not respond to requests for comment.
The security incident affects a platform with significant scale. Crunchyroll serves 15 million subscribers worldwide and offers more than 2,000 titles in over 12 languages. The company operates as a joint venture between U.S.-based Sony Pictures Entertainment and Japan-based Aniplex. Sony acquired the streaming service in 2020 for $1.18 billion. In response to the incident, the company has emphasized its collaborative response. “Our investigation is ongoing, and we continue to work with leading cybersecurity experts,” Crunchyroll said in a statement, adding that it has not identified evidence of ongoing unauthorized access.
Why it matters
This incident highlights the persistent risk of third-party vendor vulnerabilities in large-scale consumer platforms, where a single compromised credential can expose millions of user records.