So Crunchyroll got Hacked…

Article at a glance:
- Crunchyroll may have been breached through their BPO partner Telus, with a threat actor claiming to have stolen 100 GB of user data including PII, IPs, credit card details, and watch histories.
- Crunchyroll has not acknowledged the breach publicly, and the only reason we know about this at all is because the threat actor reached out to Cyber Digest themselves.
- If the claims are true, your financial and personal data could be at risk, so there are steps you should take right now without waiting for an official statement.

Just days ago, I was making a case for why piracy will never die, but I did not expect things to go this way. I am not saying Crunchyroll is at fault for getting breached; companies get data breaches all the time. But the thing is, they’re not handling it very well. If what the threat actor claims is true, Crunchyroll should be out here communicating with the threat actor and warning their consumers to retract their data from the website. But so far, Crunchyroll hasn’t even acknowledged publicly that they’ve been hacked.
Of course, all of this remains unconfirmed, as we have no official confirmation from Crunchyroll. We just have someone claiming to be a threat actor who breached Crunchyroll and pulled away 100 gigs worth of user data. All this comes to us from Cyber Digest, since that’s who the threat actor reached out to. So be sure to support them as well, and I will link their tweet here as well. First, let’s go over the incident itself.
So what happened?
A threat actor claims to have hacked and breached Crunchyroll through their BPO partner, Telus. They basically got a Telus employee to execute a malware file, giving them access to Crunchyroll’s environment. The threat actor claims to have been shut out after about 24 hours, but within that time frame, they managed to download 100 GB worth of user data, including PII, IPs, and even credit card details. Based on the sample data they provided to Cyber Digest, they also seem to have watching histories.
Credit card details are crazy as is, but the rest of the data can be sold for targeted marketing, and well, based on the severity, may even lead to identity theft. This is a big deal, and Crunchyroll should’ve alerted its consumers by now. We probably wouldn’t even have known about this if the threat actor had not contacted Cyber Digest. If you are curious, you may find further details in this Twitter thread by Cyber Digest.
What should you do?
First and foremost, change your password immediately; if you reuse the same password elsewhere, change that too. Enable 2FA on your CR account if you haven’t already. Check your recent credit card transactions, and if you see any suspicious charges, contact your bank RIGHT NOW. Don’t wait for something to happen; be proactive. Be VERY careful while opening links in email, be especially careful for emails claiming to be from Crunchyroll. With emails and PII out in the open, you’re bound to receive tons of phishing emails.
Keep an eye out for that Crunchyroll announcement as well. They may not acknowledge this officially, but if they do, follow their instructions. Just don’t wait around if you feel your privacy is at risk. I am going this far because of the credit card stuff. Don’t wait to get robbed; protect yourself.
That is all for now
This situation sucks all around. Be very careful with your email for the next few weeks and take steps to secure your credit card. That’s the best advice I can offer right now. I hope that the threat actor is brought to justice soon and sentenced as fit. But yeah, let me know what you guys think in the comments. I will take my leave here. See ya.






