Crunchyroll has acknowledged investigating alleged unauthorized access involving a third-party vendor, but it has not confirmed the headline claim that exactly 100 GB of user data was stolen. The company said the information appeared to be primarily customer-service ticket data and that it had found no evidence of continuing unauthorized access.
Claims involving 100 GB of exfiltrated data, roughly 6.8 million users, an Okta account and a specific outsourcing company came from the threat actor and secondary reporting. Have I Been Pwned later listed 1.2 million email addresses from a supplied dataset, but that figure should not automatically be treated as the complete scope.
What Crunchyroll confirmed
Crunchyroll acknowledged that it was investigating claims of unauthorized access connected to a third-party vendor. In its follow-up statement, the company said the information appeared to be primarily customer-service ticket data and that it had found no evidence of continuing unauthorized access to its systems.
That statement confirms an incident and an active investigation. It does not confirm that exactly 100 GB was stolen, that 6.8 million users were affected, that a complete payment-card database was exposed, or that a particular outsourcing company was responsible.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
| Claim or figure | What the available evidence supports |
|---|---|
| Approximately 100 GB stolen | An estimate attributed to the threat actor; not independently confirmed by Crunchyroll. |
| Approximately 8 million support-ticket records | A number reportedly given by the attacker to BleepingComputer; not confirmed as the final incident scope. |
| Approximately 6.8 million unique email addresses | Another attacker-provided figure, not established by Crunchyroll. |
| 1.2 million email addresses | Have I Been Pwned later listed this number in the dataset provided to it. It may be a subset rather than the complete exposure. |
Where the 100 GB story came from
The initial breach narrative came from a threat actor and the cybersecurity account International Cyber Digest. Reports attributed to those sources alleged that an attacker gained access through an outsourced support worker, compromised an Okta single-sign-on account, reached a Crunchyroll support environment and exfiltrated approximately 100 GB of data.
The attacker-linked material was also described as containing email addresses, IP addresses, approximate geographic information, customer analytics and payment-related details. Those descriptions should remain attributed allegations. They are not equivalent to an independent forensic finding or a confirmation from Crunchyroll.
TechCrunch reported that the suspected environment may have been Zendesk and that the access may have involved an employee of Telus Digital, an outsourced customer-support company. Crunchyroll has not publicly confirmed in the statements covered here that Telus Digital was the vendor involved. It would therefore be inaccurate to say that Telus Digital caused the incident.
The reported timeline
- March 12, 2026: The threat actor reportedly said access began after an Okta SSO account associated with a support agent was compromised. This date and attack path remain alleged.
- March 22–23, 2026: International Cyber Digest circulated claims that an infected system belonging to an outsourcing-partner employee enabled access to Crunchyroll-related systems and that about 100 GB of customer-related data had been removed.
- March 23, 2026: Crunchyroll told GamesRadar+ that it was aware of the claims and was working with leading cybersecurity experts to investigate. Reuters also reported the company’s initial response through BleepingComputer.
- March 24, 2026: Crunchyroll gave the more specific description that the information was believed to be primarily customer-service ticket data associated with a third-party vendor. The company also said it had found no evidence of ongoing unauthorized access. TechCrunch and TechRadar reported the update.
- April 4, 2026: Have I Been Pwned added the incident to its database. It listed 1.2 million email addresses in the dataset supplied to it, while describing the wider 6.8 million-user impact as alleged.
What information may have been exposed?
Reporting based on samples of the alleged support-ticket data described names, login names, email addresses, IP addresses, approximate location information and the contents of customer-support conversations. TechRadar reported that payment information was not believed to have been accessed unless a customer had included it in a support ticket.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThis distinction matters. Support tickets can contain sensitive information that a user voluntarily typed into a conversation, but they are not the same thing as Crunchyroll’s main password database or complete payment-processing systems. The available evidence does not establish that attackers stole:
- Crunchyroll’s main password database;
- every user’s viewing history;
- all stored payment-card information;
- full credit-card numbers or CVVs across the service; or
- a complete customer-analytics database.
Some of those categories appeared in attacker or secondary-source descriptions, but they were not established by Crunchyroll’s official statement or by the Have I Been Pwned entry identified in the reporting. The practical risk is more clearly concentrated around contact details, account identifiers, support conversations and other information that could make targeted phishing more convincing.
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Why the numbers should not be combined
The headline figures describe different things. The 100 GB number is an alleged volume of data. The roughly eight million figure refers to alleged records, while 6.8 million refers to an alleged number of unique email addresses. Records can contain duplicate people or multiple tickets from the same account, so those figures cannot be treated as interchangeable.
Have I Been Pwned later reported 1.2 million email addresses from an alleged two-million-record dataset provided to it. That is the clearest independently documented exposure figure in the available record, but it should not automatically be treated as the total number of affected Crunchyroll users or the full quantity of data involved.
What Crunchyroll users should do now
1. Change a reused Crunchyroll password
Reset your Crunchyroll password by navigating to the service directly rather than following a link in an unexpected email or message. If you reused that password on email, shopping, banking or any other service, change it there as well. A breach involving support data does not prove that passwords were stolen, but password reuse turns one suspected exposure into a broader account risk.
Use a long, unique password generated and stored by a reputable password manager. Crunchyroll’s own account-security guidance recommends unique passwords and says users may want to consider a password manager for generating and storing them. Do not assume that Crunchyroll endorses any particular provider.
2. Review signed-in devices
Sign in to Crunchyroll directly, open your account settings and go to the Device Management page. Review the devices associated with the account and deactivate anything you do not recognize. If suspicious devices reappear after a password reset, contact Crunchyroll support and avoid continuing to use links supplied in unsolicited messages.
3. Watch for convincing phishing attempts
Be especially cautious of messages that use a real name, email address, IP address, location detail or a reference to a previous support conversation. Those details can make a fraudulent password-reset or payment request look genuine.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteRank #3
- RUGGED PROTECTION: Built to withstand drops, shocks, dust, and rain, keeping your data safe in tough conditions.
- MASSIVE STORAGE: 4TB capacity provides ample space for large files, backups, photos, videos, and more.
- USB-C CONNECTIVITY: Features a USB-C interface for fast, reliable data transfers with modern laptops and desktops.
- BROAD COMPATIBILITY: Works seamlessly with both Mac and PC, making it a versatile storage solution for any user.
- PORTABLE DESIGN: Compact and lightweight build makes it easy to carry your data wherever your work takes you.
Do not provide a password, full payment-card number, CVV, authentication code or other unnecessary sensitive information in a support ticket. Open the Crunchyroll website or app yourself, verify the address before signing in and treat urgent requests to pay, restore or secure an account as suspicious until confirmed through an official channel.
4. Check for notification of your email exposure
You can check whether your email appeared in a breach using Have I Been Pwned or another reputable breach-notification service. Have I Been Pwned’s listing for this incident identifies email addresses in the dataset supplied to it. A result can tell you that an address appeared in a known dataset; it cannot prove that a particular Crunchyroll account is currently under an attacker’s control.
Conversely, a result showing no match is not proof that an account was unaffected. Breach-notification databases may contain only a subset of the exposed records, and new information can emerge as investigations continue.
5. Secure the accounts that matter most
Protect the email account linked to Crunchyroll first, because control of that inbox can enable password resets for other services. Turn on multi-factor authentication wherever it is supported, review recovery addresses and phone numbers, remove unfamiliar sessions and install operating-system and browser updates.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →What is still unknown
Crunchyroll’s investigation had not publicly resolved the total amount of data accessed, the number of unique people affected, the identity of the third-party vendor, or whether any payment information appeared in individual support tickets. It also had not validated the attacker’s description of the access path through Okta, an outsourced worker or a possible Zendesk environment.
Rank #4
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
The company’s statement that it found no evidence of continuing unauthorized access is reassuring about ongoing intrusion, but it does not mean that no information was accessed earlier. The two questions are separate: whether historical data was taken, and whether an attacker still has access now.
Legal and consumer context
A federal class-action complaint concerning the alleged breach was filed on March 24, 2026. The complaint records plaintiffs’ allegations and claims for harm; it is not an adjudicated finding that every factual allegation or damage claim is true.
The Federal Trade Commission’s general breach-response guidance recommends explaining what happened, identifying the information involved and describing the protective steps offered to affected people. Those recommendations provide consumer-protection context, but they do not determine whether Crunchyroll violated a particular state, federal or international law.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Bottom line
Crunchyroll has acknowledged investigating unauthorized access involving a third-party vendor and says the information was believed to be primarily customer-service ticket data. It also says there was no evidence of continuing unauthorized access. The dramatic claims of a confirmed 100 GB theft, 6.8 million affected users, full payment-card exposure or definitive responsibility by Telus Digital go beyond what the company and the strongest available verification establish.
For users, the sensible response is straightforward: replace reused passwords, review Device Management, secure the linked email account, be alert for tailored phishing and check trusted breach-notification sources without treating either a positive or negative result as a complete forensic answer.
Source context: The account above reflects Crunchyroll statements reported by GamesRadar+, TechCrunch, TechRadar and BleepingComputer, reporting attributed to Reuters, International Cyber Digest and the threat actor, and the later Have I Been Pwned listing.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
- Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
- Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
- Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
- Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C
Frequently Asked Questions
Did Crunchyroll confirm that 100 GB of user data was stolen?
No. Crunchyroll confirmed that it was investigating unauthorized access and that the information appeared to be primarily customer-service ticket data. The 100 GB figure came from the threat actor and was not confirmed by the company.
How many Crunchyroll users were affected?
The figures are not equivalent. The attacker reportedly claimed about eight million records and 6.8 million unique email addresses. Have I Been Pwned later listed 1.2 million email addresses from a dataset supplied to it, but that may be only a subset of the incident.
Were Crunchyroll credit-card details exposed?
Available reporting does not establish that Crunchyroll’s complete payment-card database was exposed. Payment information could be at risk if a customer had included it in a support ticket, but full card numbers and CVVs were not confirmed as broadly stolen.
What should Crunchyroll users do after the reported leak?
Yes, particularly if the password was reused elsewhere. Also review the Crunchyroll Device Management page, deactivate unfamiliar devices, secure the email account connected to Crunchyroll and be cautious with password-reset or payment messages.
Free tools Windows power users keep installed
One-click scans. No signup required.
The Bottom Line
Crunchyroll confirmed an investigation into unauthorized access involving a third-party vendor and said the data appeared to be primarily customer-service ticket information. It did not confirm the alleged 100 GB theft, 6.8 million affected users, full payment-card exposure or Telus Digital’s responsibility. Users should reset reused passwords, review Device Management, secure their email account and watch for phishing.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




