{"id":11533,"date":"2026-03-23T10:03:38","date_gmt":"2026-03-23T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/23\/crunchyroll-data-breach-threat-actor-claims-exfiltration-of-100-gb-of-user-data\/"},"modified":"2026-03-23T10:03:38","modified_gmt":"2026-03-23T10:03:38","slug":"crunchyroll-data-breach-threat-actor-claims-exfiltration-of-100-gb-of-user-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/23\/crunchyroll-data-breach-threat-actor-claims-exfiltration-of-100-gb-of-user-data\/","title":{"rendered":"Crunchyroll Data Breach \u2014 Threat Actor Claims Exfiltration of 100 GB of User Data"},"content":{"rendered":"<p>    Crunchyroll Data Breach \u2014 Threat Actor Claims Exfiltration of 100 GB of User Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A threat actor has allegedly exfiltrated approximately 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant, after gaining access through a compromised employee at the platform\u2019s outsourcing partner, Telus.<\/p>\n<p>The breach, which reportedly occurred on March 12, 2026, has not been publicly acknowledged by Crunchyroll as of this writing.<\/p>\n<p>According to the threat actor, who contacted Cyber Digest, the intrusion was made possible after an employee at Telus Crunchyroll\u2019s business process outsourcing (BPO) partner executed malware on their workstation.<\/p>\n<p>This infection provided the attacker with a foothold into Crunchyroll\u2019s internal environment, enabling lateral movement into sensitive customer-facing systems, including the company\u2019s ticketing infrastructure.<\/p>\n<p>This attack vector aligns with a broader pattern observed in the Telus Digital incident confirmed on March 12, 2026, in which threat actors claimed to have stolen data from Telus and numerous companies that rely on the firm for BPO services such as customer support, AI data operations, and content moderation.<\/p>\n<p>Because BPO providers handle authentication and billing tools across multiple client environments, they remain attractive high-value targets for threat actors seeking to maximize breach scope through a single intrusion.<\/p>\n<h2 class=\"wp-block-heading\" id=\"data-compromised\"><strong>Data Exfiltration by Attackers<\/strong><\/h2>\n<p>Cyber Digest analyzed a sample of the exfiltrated data provided by the threat actor, which contained highly sensitive categories of customer information, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>IP addresses<\/li>\n<li>Email addresses<\/li>\n<li>Credit card details<\/li>\n<li>Customer analytics data (PII)<\/li>\n<\/ul>\n<p>The threat actor claims a total of 100 GB of data was pulled from Crunchyroll\u2019s customer analytics environment and ticketing system. The nature of the exposed data poses significant risks of identity theft, financial fraud, and targeted phishing campaigns for affected subscribers.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f6a8.png?ssl=1\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/203c.png?ssl=1\" alt=\"\u203c\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> BREAKING: Crunchyroll breached through outsourcing partner in India.<\/p>\n<p>A threat actor exfiltrated data from Crunchyroll&#8217;s ticketing system and also managed to pull 100 GB of personally identifiable customer analytics data.<\/p>\n<p>We&#8217;ve analyzed sample data and it includes IP\u2026 <a href=\"https:\/\/t.co\/BcxGN1Y2Lv\">pic.twitter.com\/BcxGN1Y2Lv<\/a><\/p>\n<p>\u2014 International Cyber Digest (@IntCyberDigest) <a href=\"https:\/\/twitter.com\/IntCyberDigest\/status\/2035864555805413448?ref_src=twsrc%5Etfw\">March 22, 2026<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>The threat actor stated that Crunchyroll detected and revoked their access approximately 24 hours after the initial breach on March 12, 2026. Despite the relatively short access window, the volume of data exfiltrated suggests the attacker had pre-planned the operation and moved quickly once inside.<\/p>\n<p>Perhaps more alarmingly, the threat actor told Cyber Digest that Crunchyroll has continued to ignore all communications regarding the incident and has made no public disclosure to affected customers.<\/p>\n<p>This silence is particularly concerning given that Crunchyroll was already subject to a class-action lawsuit in early 2026 over alleged unauthorized sharing of user viewing data with third-party marketing platforms.<\/p>\n<p>Crunchyroll has not responded to requests for comment at the time of publication. Cyber Security News will continue monitoring this developing story.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/crunchyroll-data-breach\/\">Crunchyroll Data Breach \u2014 Threat Actor Claims Exfiltration of 100 GB of User Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/crunchyroll-data-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crunchyroll Data Breach \u2014 Threat Actor Claims Exfiltration of 100 GB of User Data A threat actor has allegedly exfiltrated approximately 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant, after gaining access through a compromised employee at the platform\u2019s outsourcing partner, Telus. The breach, which reportedly occurred on March [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-11533","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11533"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11533"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11533\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}