
Crunchyroll, the widely popular anime streaming platform, is actively investigating an alleged data breach that may have exposed the personal information of approximately 6.8 million of its users — a significant incident that underscores the growing cybersecurity risks embedded within outsourced service ecosystems.
According to early findings, the threat actor appears to have gained initial entry not through Crunchyroll's own infrastructure, but by exploiting vulnerabilities at Telus International, a third-party firm contracted to handle Crunchyroll's customer support operations. The incident highlights a recurring challenge in enterprise security: the exposure organizations face through their vendor supply chains.
"We are aware of recent claims and are currently working closely with leading cyber security experts to investigate the matter," Crunchyroll said in an official statement, offering little additional detail as the inquiry remains ongoing.
The cybersecurity outlet Bleeping Computer reported that the threat actor proactively made contact, furnishing the publication with detailed information and purported proof of the exfiltrated data.
The attacker claims to have deployed malware targeting the workstation of a Telus International customer support agent, successfully harvesting the employee's Okta authentication credentials in the process. Leveraging that initial foothold, the threat actor then pivoted laterally across multiple platforms connected to Crunchyroll's operational stack — including Zendesk, Google Workspace Mail, Slack, Mixpanel, Jira Service Management, Wizer, and MaestroQA. The intrusion illustrates how a single compromised identity can serve as a master key to an entire interconnected software-as-a-service environment.
The hacker states that the breach was executed on March 12, with access ultimately revoked within a 24-hour window. Despite the narrow timeframe, the attacker reportedly succeeded in downloading approximately 8 million customer support ticket records from Crunchyroll's Zendesk instance, containing 6.8 million unique email addresses — a volume of data that, even within such a compressed timeline, represents a substantial exposure event.
Screenshot evidence shared with Bleeping Computer reportedly details the categories of personal information allegedly exfiltrated, encompassing full names, usernames, email addresses, IP addresses, and approximate geographic location data, in addition to the contents of individual support tickets. Notably, core financial data does not appear to have been compromised; however, any partial payment details — such as the last four digits of a card number or an expiration date — that a user may have included within a support ticket would potentially be among the stolen records.
The threat actor further claims to have issued a $5 million ransom demand directly to Crunchyroll, asserting that the company has yet to respond to the extortion attempt.
This Tweet is currently unavailable. It might be loading or has been removed.
Corroborating the account, the International Cyber Digest on X also reported receiving independent screenshot evidence of the breach from the same actor, additionally claiming that the total volume of stolen data reached approximately 100GB.
Threat intelligence firm SOCRadar further noted that a post surfaced on an underground hacker forum on the same date as the alleged intrusion, listed under the title "Crunchyroll email and IP." The forum post featured redacted sample data purportedly sourced from the breach, a common tactic used to establish credibility within threat actor communities.
Adding a layer of complexity to the incident, Telus International separately confirmed to Bleeping Computer that on March 12, the company sustained a breach attributed to the prolific hacker collective ShinyHunters. However, investigators and analysts currently believe the Crunchyroll-related compromise at Telus is a separate and unrelated incident, suggesting that Telus may have faced simultaneous but distinct threat actor activity on the same day — a coincidence that warrants continued scrutiny.
As of the time of publication, Crunchyroll has not issued any direct communication or formal acknowledgement to its user base regarding the potential scope of the breach or any recommended protective measures.