Skip to main content

Crunchyroll investigates mass data breach claim

Reuters reported that attackers claimed to have obtained personal data and support logs from the streaming platform Crunchyroll.

CybersecuritySeintec Team2-3 min read
Crunchyroll investigates mass data breach claim

News summary

Reuters reported that attackers claimed to have obtained personal data and support logs from the streaming platform Crunchyroll. Part of the scope originated from the attackers’ own claims and should be treated as such.

Support systems accumulate conversations and contextual data useful for subsequent phishing. Limiting retention, permissions, and exports reduces the potential damage of a breach.

Source: Reuters — 27 July 2026

What happened

Reuters reported that a group of attackers claimed to have obtained personal data and support records from Crunchyroll, the Sony-owned anime streaming platform. The company confirmed it was investigating the claim, though part of the disclosed scope came from the attackers' own statements, which should be treated cautiously until independently verified rather than taken at face value.

Customer support systems tend to build up conversations, screenshots and contact details that don't always get the same level of protection as core databases, making them an attractive target for anyone looking for information that can be reused in later fraud, from convincing follow-up scams to account takeover attempts.

What it teaches a business with customer support

When an attack isn't fully confirmed, reasonable doubt doesn't excuse inaction: reviewing access to the ticketing system, rotating support agent credentials and checking logs for bulk exports are steps that don't depend on the claim being fully verified first.

The case also shows that an incident at a third-party service, such as ticketing software, can expose a company's data even though its own infrastructure was never compromised.

What to review

Measures that limit the damage if the support system is compromised:

  • What personal data remains stored in the support conversation history and for how long.
  • Who can export data in bulk from the ticketing tool and whether that action is logged.
  • Whether support agents use two-factor authentication and passwords separate from other internal systems.
  • How an eventual confirmed data exposure would be communicated to customers.

Frequently Asked Questions

Was the data theft confirmed?
Crunchyroll said it was investigating the claim; part of the known information came from the attackers' own statements.
Why is a customer support system sensitive?
Because it accumulates contact details and conversations that can be used to prepare fraud or targeted phishing campaigns.
Should you wait for confirmation before acting?
No. Reviewing access and credentials for the support system is reasonable as soon as a credible claim emerges.

Concepts mentioned in this article: Retention · Phishing

At Seintec, we can help you review how a similar scenario would affect your business and define the most appropriate technical measures. Contact us and an expert will study your case.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.