Last updated: October 1, 2026. Crunchyroll says it is investigating a security incident involving customer-service ticket data handled through a third-party vendor. A threat actor claimed to have downloaded about 8 million support records, including 6.8 million unique email addresses, but Crunchyoll has not confirmed those figures or the number of affected people.
What Crunchyroll confirmed
On March 23–24, 2026, Crunchyroll acknowledged recent claims of unauthorized access and said it was working with cybersecurity experts. In a follow-up statement, the company said the information appeared to be primarily limited to customer-service ticket data after an incident involving a third-party vendor. Crunchyroll also said it had not identified evidence of continuing unauthorized access and was monitoring the situation.
Those statements confirm an incident involving data handled for Crunchyroll, not the attacker’s full description of what was taken. The company has not publicly confirmed the exact number of affected people, the amount of data exfiltrated, the attacker’s identity, every system allegedly accessed, or all categories of information described in threat-actor posts. TechCrunch reported Crunchyroll’s statements and the company’s investigation.
How the alleged compromise happened
The reported access path centers on an outsourced support identity rather than a publicly confirmed compromise of Crunchyroll’s core streaming infrastructure.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Alleged start: The threat actor said access began on March 12, 2026, at approximately 9 p.m. Eastern Time.
- Identity used: The attacker allegedly compromised an Okta single-sign-on account used by a customer-support agent.
- Vendor connection: Reporting linked that agent to Telus International/Telus Digital, a business-process outsourcing provider. Crunchyroll referred to a third-party vendor but did not publicly confirm the vendor relationship in the cited reporting.
- Support systems: The account allegedly provided access to support platforms, including Zendesk.
- Data claimed: The attacker said customer-support ticket records were downloaded.
Reports described malware or stolen credentials as possible initial-access methods, but that detail remains an allegation or secondary reporting—not a final forensic finding. Reuters reporting syndicated by CNA described the alleged Okta and support-agent access.
What information may be involved
Reported samples or allegations said support records could contain:
- Names and usernames
- Email addresses
- IP addresses
- General geographic-location information
- The contents of customer-service conversations
- Other details customers entered into support requests
Support tickets can contain sensitive material without implying that Crunchyroll’s primary account database was accessed. Reports also said payment-card details appeared in some tickets because customers had voluntarily typed them into support requests. That is materially different from evidence that a payment processor or stored card vault was breached. AUSCERT summarized the reported ticket categories and payment-data qualification.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How large was the incident?
The headline numbers come from the alleged attacker, not from an independently verified Crunchyroll count.
| Figure | What it represents | Status |
|---|---|---|
| About 8 million | Support-ticket records allegedly downloaded | Threat-actor claim; not independently verified |
| About 6.8 million | Unique email addresses allegedly present in those records | Threat-actor claim; not independently verified |
Neither figure equals a confirmed number of Crunchyroll customers. One person may have submitted multiple tickets, records may be historical or duplicated, and an email address in a ticket does not prove that the associated account was taken over. Crunchyroll’s confirmed position is limited to an incident involving customer-service data and an ongoing investigation.
Were passwords, the streaming service or payment systems breached?
The available reporting does not establish that Crunchyroll’s primary authentication database, stored payment-card database or streaming platform was compromised. It also does not prove that Crunchyroll passwords were stolen.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
That is not a guarantee that every account is safe. A support ticket may contain information a customer supplied, and an exposed email address can make targeted phishing more convincing. Treat claims about “millions of hacked accounts,” a 100GB download or leaked card numbers as unverified unless Crunchyroll, a regulator or a credible forensic report later confirms them.
What “no ongoing access” means
Crunchyroll said it had not identified evidence of continuing unauthorized access. That describes the company’s investigation at the time of its statement. It does not prove that every copied file was deleted, that an attacker retained no offline copy, or that phishing and identity-abuse risks ended when the access path was closed.
There is also a timeline ambiguity in public reporting: one account described records dating to early 2025, while other reports placed the alleged intrusion on March 12, 2026. Those descriptions may refer to the age of records in the stolen database rather than continuous access until 2025. They should not be merged into a single confirmed timeline.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What Crunchyroll users should do now
Change reused passwords
If you used your Crunchyroll password on another service, change it everywhere it was reused—starting with email, banking, shopping and social-media accounts. Set a unique Crunchyroll password and enable multifactor authentication if the account offers it.
Expect convincing phishing
- Do not click password-reset links in unsolicited messages.
- Open Crunchyroll by typing its known official address or using the official app.
- Check the sender domain instead of trusting display names.
- Never give a one-time authentication code to someone claiming to be support.
- Be especially cautious about messages mentioning a prior ticket, refund, subscription problem or account suspension.
Review account and email activity
Check recent login notifications, unfamiliar devices or sessions, unexpected password-reset messages, subscription and billing activity, and email-forwarding rules if you suspect your email account is being targeted.
Handle card concerns proportionately
Contact your card issuer if you ever typed a full card number, security code or other highly sensitive financial information into a support ticket. The available reporting does not establish that Crunchyroll’s stored payment-card database was accessed.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Consider a credit freeze only for identity-theft data
For U.S. readers, a freeze is most relevant if a ticket may have included a Social Security number or comparable identity information—not merely an email address or IP address. Use the official Equifax, Experian and TransUnion freeze pages, and consult the FTC’s identity-theft guidance.
What remains unknown
- The confirmed number of affected individuals and records
- The exact date range represented in the tickets
- Whether every system named by the attacker was accessed
- The precise relationship between Crunchyroll and the reported Telus-linked account
- Whether regulators or affected users will receive formal notifications
- Whether copied data was recovered or destroyed
Until an official incident notice, regulatory filing or final forensic report provides those details, the careful description is a third-party-access incident affecting Crunchyroll customer-support data, with the largest volume estimates still unverified.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




