---
title: "Crunchyroll customer-service ticket data incident"
description: "Evidence-backed account of Crunchyroll customer-service ticket data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/crunchyroll-customer-service-ticket-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/crunchyroll-customer-service-ticket-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/crunchyroll-customer-service-ticket-data-incident-2026/stix.json"
---

# Crunchyroll customer-service ticket data incident

Crunchyroll confirmed an incident involving a third-party vendor and information primarily limited to customer-service ticket data. Customer-service ticket data observed by BleepingComputer and a separately quantified verified HIBP email-address corpus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[Crunchyroll](https://www.crunchyroll.com/) confirmed an incident involving a third-party vendor and information primarily limited to customer-service ticket data. [2](#source-2)

## Impact

Customer-service ticket data observed by BleepingComputer and a separately quantified verified HIBP email-address corpus. [1](#source-1) [2](#source-2)

Documented data types include:

- Customer service records — Crunchyroll's stated primary information boundary and BleepingComputer's observed support-ticket samples. [1](#source-1) [2](#source-2)
- Names — Observed by BleepingComputer in customer-support ticket samples; not asserted for every record. [1](#source-1) [2](#source-2)
- Contact information — Email addresses are the sole HIBP DataClass for the verified subset; BleepingComputer also observed them in ticket samples. [1](#source-1) [2](#source-2)
- Message content — Contents of customer-support tickets observed by BleepingComputer; content varied by what customers submitted. [1](#source-1) [2](#source-2)
- Geographic location information — General geographic locations observed by BleepingComputer in ticket samples; not asserted as precise geolocation or for every record. [1](#source-1) [2](#source-2)
- IP addresses — Observed by BleepingComputer in customer-support ticket samples; not asserted for every record. [1](#source-1) [2](#source-2)
- Usernames and account identifiers — Login names observed by BleepingComputer in customer-support ticket samples; not asserted for every record. [1](#source-1) [2](#source-2)

A cited record reports 1,195,684 records (Unique email addresses in the verified HIBP subset; not a Crunchyroll-confirmed count of affected users, tickets, or people and not the alleged 6.8 million total; as of 2026-04-04). [1](#source-1) [2](#source-2)

Crunchyroll said the information was primarily limited to customer-service ticket data following an incident with a third-party vendor. [2](#source-2)

## Timeline

### March 12, 2026 — Documented event

HIBP BreachDate; Crunchyroll confirmed the incident but did not establish this as an exact intrusion, detection, or containment date. [1](#source-1)

### March 23, 2026 — Public disclosure

Date BleepingComputer published Crunchyroll's direct statements. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Crunchyroll said it had not identified evidence of ongoing system access related to the claims and was continuing to monitor the situation. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/crunchyroll-customer-service-ticket-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Crunchyroll breach record

advisory · Have I Been Pwned · Apr 4, 2026

<https://haveibeenpwned.com/api/v3/breach/Crunchyroll>

<a id="source-2"></a>

### Crunchyroll probes breach after hacker claims to steal 6.8M users' data

news · BleepingComputer · Mar 23, 2026

<https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   March 2026 Crunchyroll customer-service data breach: Crunchyroll, LLC
2. **Occurred At · 80% confidence · current**  
   March 2026 Crunchyroll customer-service data breach: 2026-03-12
3. **Resulted In · 95% confidence · current**  
   March 2026 Crunchyroll customer-service data breach: Crunchyroll customer-service ticket corpus
4. **Exposed Data Category · 100% confidence · current**  
   Crunchyroll customer-service ticket corpus: Customer service records
5. **Resulted In · 100% confidence · current**  
   March 2026 Crunchyroll customer-service data breach: Crunchyroll said the information was primarily limited to customer-service ticket data following an incident with a third-party vendor.
6. **Exposed Data Category · 90% confidence · current**  
   Crunchyroll customer-service ticket corpus: Names
7. **Exposed Data Category · 100% confidence · current**  
   Crunchyroll customer-service ticket corpus: Contact information
8. **Disclosed At · 100% confidence · current**  
   March 2026 Crunchyroll customer-service data breach: 2026-03-23
9. **Exposed Data Category · 90% confidence · current**  
   Crunchyroll customer-service ticket corpus: Message content
10. **Exposed Data Category · 90% confidence · current**  
   Crunchyroll customer-service ticket corpus: Geographic location information
11. **Exposed Data Category · 90% confidence · current**  
   Crunchyroll customer-service ticket corpus: IP addresses
12. **Exposed Record Count · 100% confidence · current**  
   Crunchyroll customer-service ticket corpus: 1,195,684 record
13. **Resulted In · 100% confidence · current**  
   March 2026 Crunchyroll customer-service data breach: Crunchyroll said it had not identified evidence of ongoing system access related to the claims and was continuing to monitor the situation.
14. **Exposed Data Category · 90% confidence · current**  
   Crunchyroll customer-service ticket corpus: Usernames and account identifiers

</details>
