this post was submitted on 23 Mar 2026
60 points (96.9% liked)

Anime

4340 readers
154 users here now

This community is the place to discuss and ask questions about anime, anime news, and related topics.

Currently airing show discussion threads are created by our resident bot, rikka@ani.social. If it doesn't make a thread for an episode that you want to discuss, see the user guide on the wiki for instructions on how to ask rikka to make a thread for you to use.

Check out our wiki to find:

Rules

More complete rules on the wiki.

Post Tags

Post tags are completely optional, but some recommended tags would include:

Related General Communities

Discord

Thanks to @NineSwords@ani.social for running the discord!


rikka

founded 2 years ago
MODERATORS
 

Apparently there has been a data breach at Crunchyroll.

100 GB of Personal Data from users including Credit Cards, Email Addresses, IP's, passwords & more... Are in possession of hackers.

source: 1, 2, 3

I couldn't find anything on their channel or their news website at this time.

edit 1:

What Data Was Stolen? A 100GB Treasure Trove

Initial samples provided by the threat actors suggest a wide-reaching compromise. The 100 GB haul is not just a collection of names and email addresses; it is a deep dive into a customer’s streaming habit, personal information and financial data.

1. Personally Identifiable Information (PII)

The most immediate risk to users comes from the exposure of:

Full Names and Email Addresses: Perfect fuel for future, more targeted phishing campaigns. IP Addresses: Which can be used to approximate user locations and track digital footprints. Account History: Details on subscription tiers and account age.

2. The Financial Risk: Credit Card Details

Perhaps the most alarming claim is the theft of credit card information. While modern systems typically “mask” credit card numbers (showing only the last four digits), the ticketing system often contains unencrypted logs or “receipt” snapshots that may have been swept up in the exfiltration. If full card details were present in support tickets (where users occasionally send screenshots to resolve billing issues), the risk of financial fraud is extreme.

3. Customer Analytics & Support Tickets

By gaining access to the ticketing system, the attacker has access to every conversation users have had with Crunchyroll support. This includes:

Personal complaints. Billing disputes. Verification documents (if any were uploaded).

source

Still no word from Crunchy itself.

edit 2:

Just a bit more tidbits, but still no news from Crunchy itself (emphasis mine).

The threat actor stated that Crunchyroll detected and revoked their access approximately 24 hours after the initial breach on March 12, 2026. Despite the relatively short access window, the volume of data exfiltrated suggests the attacker had pre-planned the operation and moved quickly once inside.

Perhaps more alarmingly, the threat actor told Cyber Digest that Crunchyroll has continued to ignore all communications regarding the incident and has made no public disclosure to affected customers.

This silence is particularly concerning given that Crunchyroll was already subject to a class-action lawsuit in early 2026 over alleged unauthorized sharing of user viewing data with third-party marketing platforms.

Crunchyroll has not responded to requests for comment at the time of publication. Cyber Security News will continue monitoring this developing story.

Source

edit 3:

In a statement to GamesRadar+, a Crunchyroll spokesperson said, "We are aware of recent claims and are currently working closely with leading cybersecurity experts to investigate the matter."

source

So, let me get this straight. They are aware, yet here I am checking my inbox and not seeing a warning about a (potential) breach.

top 10 comments
sorted by: hot top controversial new old
[–] RightHandOfIkaros@lemmy.world 10 points 17 hours ago* (last edited 17 hours ago) (1 children)

Changed my account password and cancelled my subscription.

In their exit survey, I told them the reason I am cancelling is because "your 'business' is a massive cyber security liability, and I do not plan to return unless you give my account the most premium tier eubscription for free, forever."

So its back to the seas for me. I tried being a good person and doing it legally, but if that comes with the massive caveat that my data is going to be harvested/stolen multiple time, then I would rather pirate. At least if my data gets stolen from malware, I didnt pay for it.

[–] lemmyng@lemmy.world 3 points 16 hours ago (1 children)

Never been a better time to return to the seas, friend!

[–] RightHandOfIkaros@lemmy.world 6 points 16 hours ago (1 children)

I mean, I never really left, but its like, how can businesses honestly expect customers to buy their product when the objectively better (and safer in this case) experience is to just pirate the content?

[–] lemmyng@lemmy.world 2 points 13 hours ago

Right? Why give my money and valuable sensitive data to a shillionaire company that doesn't give a shit about my safety when I can anonymously pirate for $Free.99?

[–] mnemonicmonkeys@sh.itjust.works 7 points 18 hours ago

I would like to remind everyone that Crunchyroll is owned by Sony, which has done a generally terrible job at preventing and managing data breaches for decades now

[–] Philharmonic3@lemmy.world 2 points 15 hours ago (1 children)

Would someone just kill me already? I can't have fucking anything good.

[–] NineSwords@ani.social 4 points 14 hours ago

Nah man. If you considered Crunchyroll "good" before this breach you still have so much to live for since literally everything must be great ;)

[–] alphacyberranger@sh.itjust.works 3 points 20 hours ago
[–] ReluctantlyZen@ani.social 8 points 1 day ago

Cool, time to update my password. Everything else is aliased thankfully

[–] AntiBullyRanger@ani.social 0 points 1 day ago* (last edited 1 day ago)

iirc, ↓ like ᚦ occ..

🙅‍♀️📉📖