Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data
On March 12, 2026, a significant data breach allegedly occurred at Crunchyroll, an anime streaming service owned by Sony. Approximately 100 GB of personally identifiable information (PII) was reportedly exfiltrated by a threat actor. The security breach…
On March 12, 2026, a significant data breach allegedly occurred at Crunchyroll, an anime streaming service owned by Sony. Approximately 100 GB of personally identifiable information (PII) was reportedly exfiltrated by a threat actor. The security breach was traced back to an employee at Telus, Crunchyroll's business process outsourcing (BPO) partner, who inadvertently executed malware on their workstation.
The intrusion enabled the attacker to access Crunchyroll's internal systems, including its customer-facing ticketing infrastructure. This incident appears consistent with patterns observed in the Telus Digital breach, which was confirmed on the same day. In the latter, threat actors claimed to have stolen data from Telus and other companies relying on Telus for BPO services, including customer support and content moderation.
The exfiltrated data reportedly includes the following sensitive information:
IP addresses Email addresses Credit card details Customer analytics data (PII)
On March 12, 2026, a significant data breach allegedly occurred at Crunchyroll, an anime streaming service owned by Sony.
The exposure of such data poses risks of identity theft, financial fraud, and phishing attacks.
The threat actor claims that Crunchyroll detected and revoked their access approximately 24 hours after the initial breach. Despite this, the volume of data exfiltrated suggests rapid execution of the attack. As of the publication date, Crunchyroll has not publicly acknowledged the breach or responded to communications about the incident.
This breach has significant implications, particularly as Crunchyroll was already facing legal challenges related to alleged unauthorized data sharing earlier in 2026. The lack of public disclosure has raised concerns among stakeholders.
Further updates will be monitored as the situation develops.
Based on reporting by Cyber Security News.
