Crunchyroll Data Breach: 100GB of User Data Allegedly Exfiltrated
Key Takeaways Sony-owned anime streaming service Crunchyroll has reportedly suffered a significant data breach. Approximately 100GB of sensitive user data, including credit card details and email...
Key Takeaways
- Sony-owned anime streaming service Crunchyroll has reportedly suffered a significant data breach.
- Approximately 100GB of sensitive user data, including credit card details and email addresses, was allegedly exfiltrated.
- The intrusion was reportedly facilitated through a compromised employee workstation at Telus, Crunchyroll’s business process outsourcing (BPO) partner.
- Crunchyroll has not publicly acknowledged the incident, despite claims from the threat actor that they were informed.
Crunchyroll Hit by Alleged 100GB Data Breach via Outsourcing Partner Telus
Anime streaming giant Crunchyroll, a subsidiary of Sony, is facing allegations of a substantial data breach. A threat actor claims to have exfiltrated approximately 100 gigabytes of personally identifiable information (PII) from the platform. The breach reportedly originated through a compromised employee account at Telus, a key business process outsourcing (BPO) partner for Crunchyroll.
Table Of Content
The alleged incident, which occurred on March 12, 2026, has yet to be publicly confirmed or acknowledged by Crunchyroll. This silence comes even as details emerge from the purported attacker, who contacted Cyber Digest to share information about the intrusion.
Intrusion Vector: Compromised BPO Partner
According to the threat actor, the breach was initiated after an employee at Telus, which provides services like customer support, AI data operations, and content moderation to Crunchyroll, executed malicious software on their workstation. This malware infection provided the initial access point, allowing the attacker to establish a foothold within Crunchyroll’s internal network. From there, the perpetrator reportedly moved laterally, gaining access to sensitive customer-facing systems, including the company’s ticketing infrastructure.
This attack methodology mirrors a broader pattern observed in the Telus Digital incident, which was confirmed on March 12, 2026. In that separate but related event, threat actors also claimed to have stolen data from Telus itself and multiple other companies reliant on its BPO services. The reliance of numerous organizations on BPO providers for critical functions like authentication and billing makes these partners attractive targets for cybercriminals seeking to maximize the impact of a single breach.
Exfiltrated Data Categories and Risks
Cyber Digest reportedly analyzed a sample of the data provided by the threat actor. This sample contained highly sensitive categories of customer information, raising significant concerns for Crunchyroll subscribers:
- IP addresses
- Email addresses
- Credit card details
- Customer analytics data (containing PII)
The attacker asserts that a total of 100 GB of data was extracted from Crunchyroll’s customer analytics environment and ticketing system. The nature of this exposed information presents substantial risks, including potential identity theft, financial fraud, and the execution of highly targeted phishing campaigns against affected users. The full scope of the compromise is still being assessed, but the implications for user privacy are severe. The incident was highlighted by International Cyber Digest on X (formerly Twitter) on March 22, 2026.
Crunchyroll’s Response and Past Legal Issues
The threat actor indicated that Crunchyroll detected and subsequently revoked their access approximately 24 hours after the initial intrusion on March 12, 2026. Despite this relatively brief access window, the sheer volume of data reportedly exfiltrated suggests a well-planned operation and rapid data extraction once inside the network.
Perhaps more troubling, the attacker informed Cyber Digest that Crunchyroll has allegedly ignored all communications regarding the incident and has not made any public disclosure to its affected customers. This lack of transparency is particularly concerning, especially given that Crunchyroll faced a class-action lawsuit in early 2026. That lawsuit alleged unauthorized sharing of user viewing data with third-party marketing platforms, indicating a prior history of scrutiny regarding user data handling.
As of this report, Crunchyroll has not responded to requests for comment. HackersRadar will continue to monitor this evolving situation closely.
What You Should Do
- Monitor Financial Statements: Carefully review credit card and bank statements for any suspicious or unauthorized activity.
- Change Passwords: Immediately change your Crunchyroll password and any other accounts where you might have reused the same password. Use strong, unique passwords for all online services.
- Enable Multi-Factor Authentication (MFA): Activate MFA on your Crunchyroll account and all other critical online accounts to add an extra layer of security.
- Be Wary of Phishing Attempts: Exercise extreme caution with emails, messages, or calls purporting to be from Crunchyroll or other services, especially those asking for personal information or login credentials.
- Review Privacy Settings: Check and adjust privacy settings on your Crunchyroll account to limit data sharing where possible.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.