Crunchyroll Confirms Data Breach Affecting Millions of Users
On March 23, reports surfaced regarding a data breach impacting Crunchyroll, a prominent anime streaming platform. The initial reports were shared on X (formerly Twitter) by International Cyber Digest and subsequently detailed by BleepingComputer.
The hacker, who contacted BleepingComputer, claimed to have breached Crunchyroll on March 12 through malware infecting a computer belonging to an employee of an outsourcing company with access to Crunchyroll support tickets. The hacker alleges they downloaded records from approximately eight million support tickets, containing nearly seven million unique email addresses.
Crunchyroll’s Response
Crunchyroll representatives provided Polygon with the following statement on March 23: “We are aware of recent claims and are currently working closely with leading cybersecurity experts to investigate the matter.”
On March 24, Crunchyroll issued a further statement and update:
“Our investigation is ongoing and we continue to work with leading cybersecurity experts. At this time, we believe that the information is primarily limited to customer service ticket data following an incident with a third-party vendor. We have not identified evidence of ongoing access to systems in relation to these claims. We are continuing to monitor the situation closely.”
What Data Was Compromised?
Crunchyroll’s statement confirms the breach and the compromise of support ticket data. According to BleepingComputer, the exposed data primarily includes general information found within support tickets, such as users’ names, login names, email addresses, IP addresses, general geographic locations, and the content of the support tickets themselves.
Although initial reports suggested potential exposure of credit card information, BleepingComputer confirmed that credit card details were only exposed when customers included them within the support ticket content. In most cases, this involved limited information like the last four digits or expiration dates, with only a small number of tickets containing full card numbers, according to the hacker.
Keep reading