
Crunchyroll, a well-known anime streaming service, is investigating a potential security incident where hackers assert they obtained private data belonging to roughly 6.8 million users.
Crunchyroll initially informed BleepingComputer that they are aware of the claims and actively collaborating with cybersecurity experts to investigate.
In a subsequent announcement, Crunchyroll stated that their investigation is ongoing with the assistance of cybersecurity professionals. They currently believe the compromised data is limited to customer service ticket information stemming from an incident with a third-party vendor.
Crunchyroll also stated they haven’t discovered any indication of continued unauthorized system access related to these claims and are closely monitoring the situation.
This announcement follows a hacker contacting BleepingComputer last Thursday and alleging they infiltrated Crunchyroll on March 12th at 9 PM EST by gaining access to a Crunchyroll support agent’s Okta SSO account.
The support agent is reportedly an employee of Telus International, a business process outsourcing (BPO) firm, with access to Crunchyroll support tickets. The hackers claim they used malware to compromise the agent’s computer and steal their login information.
Screenshots shared with BleepingComputer suggest these credentials provided access to several Crunchyroll applications, including Zendesk, Wizer, MaestroQA, Mixpanel, Google Workspace Mail, Jiro Service Management, and Slack.
The attackers claim to have downloaded 8 million support ticket records from Crunchyroll’s Zendesk using this access. These records allegedly contain 6.8 million unique email addresses.
Support ticket samples viewed and then deleted by BleepingComputer included a variety of information, such as the user’s name, login name, email address, IP address, general location, and the content of the support requests.
While some reports suggest credit card information was compromised, BleepingComputer confirmed that credit card data was exposed only if the customer shared it within the support ticket.
According to the hacker, the majority of exposed credit card data included basic information like the last four digits or expiration dates, with only a small number containing complete card numbers.
The support tickets examined by BleepingComputer all mentioned Telus, supporting the hacker’s assertion that they compromised a BPO employee.
The attacker says their access was revoked after 24 hours, but they managed to steal data up to mid-2025.
The hacker claims to have sent extortion emails to Crunchyroll, demanding $5 million to prevent the public release of the data, but received no response.
While the attack targeted a Telus employee, BleepingComputer was informed that it’s unrelated to the large-scale breach at Telus Digital by the ShinyHunters extortion group.
Business process outsourcing companies have become attractive targets for hackers in recent years because they frequently manage customer service, billing, and internal authentication for numerous organizations.
As a result, hackers can compromise a single BPO employee to gain access to large volumes of customer and corporate data across multiple organizations.
In the past year, hackers have exploited BPOs by bribing insiders with legitimate access, using social engineering to trick support staff into granting unauthorized access, and compromising BPO employee accounts to infiltrate internal systems.
In one prominent example, attackers impersonated an employee and persuaded a Cognizant help desk agent to grant them access to a Clorox employee account, which allowed them to breach Clorox’s network.
Major retailers have also confirmed that social engineering attacks on support personnel led to ransomware and data theft incidents.
Marks & Spencer confirmed that social engineering was used to breach its network, and Co-op reported data theft after a ransomware attack similarly targeted support staff access.
Following the attacks on M&S and Co-op, the U.K. government provided guidance on preventing social engineering attacks on help desks and BPOs.
In some cases, hackers directly target BPO employee accounts to access the customer data they manage.
In October, Discord revealed a data breach, allegedly exposing data from 5.5 million users after its Zendesk support system was compromised.
Update 3/23/25 7:51 PM ET: Story updated with additional statement from Crunchyroll.
#6.8m #alleges #breach #crunchyroll #data #hacker #investigates #news #records #theft #user — News
© Bulletproof Servers. All rights reserved.