Sony-owned anime streaming service Crunchyroll has experienced a data breach after hackers infiltrated a third-party vendor to gain access to customer support ticket data. The breach has exposed information tied to around 6.8 million users, prompting an ongoing investigation into the scope of the incident.
According to reporting from BleepingComputer, the company confirmed it is investigating claims that a threat actor accessed and extracted data.
International Cyber Digest reported on X:
“Crunchyroll [was] breached through an outsourcing partner in India. A threat actor exfiltrated data from Crunchyroll's ticketing system and also managed to pull 100GB of personally identifiable customer analytics data."
The sample data included IP addresses, email addresses, location, and support ticket contents.
“An employee of their outsourcing partner Telus had executed malware on his system, which gave a threat actor access to Crunchyroll's environment,” the post stated.
"We analyzed sample JSON files exported from their Zendesk. And found customer support conversations, user profiles, and significant PII found across structured fields and free-text bodies," International Cyber Digest added in another post.
Third-Party Compromise Exposes CX Weak Point
The breach appears to have originated from a compromised account belonging to a customer support agent employed by an outsourcing provider, reportedly Telus International.
The attackers contacted BleepingComputer claiming to have breached Crunchyroll on March 12th at 9PM EST, after gaining access to the Okta single sign-on (SSO) account of one of the company’s support agents.
Once inside, the attackers reportedly accessed multiple internal systems, including support and collaboration tools, and downloaded roughly 8 million support ticket records related to around 6.8 million unique email addresses.
While some reports suggested exposure of payment data, analysis indicates that financial details appeared only in cases where users manually entered them into support tickets—and were typically partial (such as last four digits).
Crunchyroll told BleepingComputer:
"We have not identified evidence of ongoing access to systems in relation to these claims."
Screenshots shared with BleepingComputer indicate that the attackers gained access to various Crunchyroll applications, including Zendesk, Wizer, MaestroQA, Mixpanel, Google Workspace Mail, Jiro Service Management, and Slack. BleepingComputer confirmed that credit card details, such as the expiry date and last four digits, that were shared in the support tickets were exposed.
The exported Zendesk data adds another layer to the issue: blending structured data with unstructured customer conversations.




