Crunchyroll investigates mass data breach claim
Reuters reported that attackers claimed to have obtained personal data and support logs from the streaming platform Crunchyroll.

News summary
Reuters reported that attackers claimed to have obtained personal data and support logs from the streaming platform Crunchyroll. Part of the scope originated from the attackers’ own claims and should be treated as such.
Support systems accumulate conversations and contextual data useful for subsequent phishing. Limiting retention, permissions, and exports reduces the potential damage of a breach.
Source: Reuters — 27 July 2026
What happened
Reuters reported that a group of attackers claimed to have obtained personal data and support records from Crunchyroll, the Sony-owned anime streaming platform. The company confirmed it was investigating the claim, though part of the disclosed scope came from the attackers' own statements, which should be treated cautiously until independently verified rather than taken at face value.
Customer support systems tend to build up conversations, screenshots and contact details that don't always get the same level of protection as core databases, making them an attractive target for anyone looking for information that can be reused in later fraud, from convincing follow-up scams to account takeover attempts.
What it teaches a business with customer support
When an attack isn't fully confirmed, reasonable doubt doesn't excuse inaction: reviewing access to the ticketing system, rotating support agent credentials and checking logs for bulk exports are steps that don't depend on the claim being fully verified first.
The case also shows that an incident at a third-party service, such as ticketing software, can expose a company's data even though its own infrastructure was never compromised.
What to review
Measures that limit the damage if the support system is compromised:
- What personal data remains stored in the support conversation history and for how long.
- Who can export data in bulk from the ticketing tool and whether that action is logged.
- Whether support agents use two-factor authentication and passwords separate from other internal systems.
- How an eventual confirmed data exposure would be communicated to customers.
Frequently Asked Questions
- Was the data theft confirmed?
- Crunchyroll said it was investigating the claim; part of the known information came from the attackers' own statements.
- Why is a customer support system sensitive?
- Because it accumulates contact details and conversations that can be used to prepare fraud or targeted phishing campaigns.
- Should you wait for confirmation before acting?
- No. Reviewing access and credentials for the support system is reasonable as soon as a credible claim emerges.
Concepts mentioned in this article: Retention · Phishing
At Seintec, we can help you review how a similar scenario would affect your business and define the most appropriate technical measures. Contact us and an expert will study your case.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.