What actually happened
On March 12, 2026, a threat actor gained access to Crunchyroll's internal systems. But the breach didn't start at Crunchyroll's headquarters — it started at a company most subscribers have never heard of.
Crunchyroll outsources its customer support to Telus, a business process outsourcing partner based in India. An employee at Telus was targeted with a phishing email, clicked something they shouldn't have, and malware was installed on their workstation. That malware captured the employee's Okta SSO credentials — the single set of login details that granted access to multiple Crunchyroll systems simultaneously.
From that one compromised workstation, the attacker moved laterally into Crunchyroll's Zendesk support system, internal Slack, and Google Workspace. They had access for approximately 24 hours before Crunchyroll detected the intrusion and cut them off.
Here is the sequence of events:
What was stolen — and what wasn't
There has been a lot of conflicting reporting on this, so let me separate what is confirmed from what is claimed but unverified.
| Data Type | Status | Risk Level | Why It Matters |
|---|---|---|---|
| Email addresses | ✅ Confirmed | HIGH | Enables targeted phishing and credential stuffing across other platforms |
| Usernames / Login names | ✅ Confirmed | HIGH | Many users reuse usernames across platforms, aiding account targeting |
| IP addresses | ✅ Confirmed | MED | Reveals approximate location; enables geographically convincing scams |
| Geographic location (approx.) | ✅ Confirmed | MED | Used to personalise phishing emails ("We noticed a login from your city…") |
| Support ticket contents | ✅ Confirmed | HIGH | Contains personal information users volunteered — see below |
| Full credit card numbers | ❌ Not confirmed | LOW | Crunchyroll uses third-party payment processors; full card data unlikely in tickets |
| Passwords (hashed or plain) | ❌ Not confirmed | LOW | Zendesk doesn't store login passwords; not part of the support ticket system |
| Partial card details (last 4 digits, expiry) | ⚠️ Possible | MED | Could appear in support tickets discussing billing disputes |
The most important thing to understand: the absence of full credit card numbers does not mean you are safe. The combination of confirmed stolen data — email, username, approximate location, and support ticket contents — is more than enough to run a highly convincing phishing campaign against millions of fans.
Why your support ticket contents are the real problem
This is the part that most breach coverage glosses over, and it's the most important thing I can explain to you as a fan who may have contacted Crunchyroll support at any point.
Think about what you actually write in a support ticket. Not abstract data — real words. Things like:
- "I was charged twice, my card ending in 4821 shows two transactions on April 3rd"
- "I can't log in, my email is [email protected] and my account is linked to my Facebook"
- "My account is being used by someone else, I'm currently in London but the login is from Seoul"
- "I'm a student at Kyoto University, my .edu email doesn't work for the discount"
That is not generic data. That is a personalised dossier on you — written in your own words, containing details that a stranger would have no way of knowing unless you told them. And now, criminals have it.
This is why the phishing threat from this breach is significantly higher than a typical email/password dump. The attackers don't just know who you are — they know the context of your relationship with Crunchyroll, in your own words.
The credential stuffing attack that's coming
Even setting aside phishing, there is a second threat that the fan community is almost entirely unaware of: credential stuffing.
Here's how it works. A credential stuffing attack doesn't try to guess your password. It takes known, real username-and-email combinations from a breach — exactly like this one — and automatically tries them against other platforms: your email account, your Netflix, your bank, your Discord, your Steam.
The bet attackers are making is simple: that you used the same email and password on Crunchyroll as you did somewhere else. Statistically, that bet pays off at scale. Even a 1% success rate across 6.8 million accounts means 68,000 accounts broken into on other platforms, using credentials stolen from this breach.
This is why "change your Crunchyroll password" is necessary but incomplete advice. The question isn't just whether your Crunchyroll account is safe — it's whether the same credentials you used there are protecting anything else.
6 steps to take right now
These are ordered by priority. Do them in sequence.
Change your Crunchyroll password immediately
Go to crunchyroll.com, log in, and change your password to something unique — not used on any other site, ever. Use at least 16 characters with a mix of letters, numbers, and symbols. If you struggle to remember complex passwords, use a password manager like Bitwarden (free) or 1Password.
Change the same password everywhere else you used it
This is the step most people skip, and it's the most important one. If your Crunchyroll password is the same as your email, your bank, your gaming accounts, or your social media — change all of them. Each one needs to be unique. Yes, this takes time. Do it anyway.
Treat every "Crunchyroll" email as a scam for the next 12 months
Do not click any link in an email claiming to be from Crunchyroll — even if it looks perfect. If Crunchyroll genuinely needs you to do something, go directly to crunchyroll.com by typing it in your browser. Criminals now have a confirmed list of 6.8 million active Crunchyroll users to target, and the phishing emails will be convincing — they may reference your location, billing history, or support interactions.
Check your bank and credit card statements weekly for the next 6 months
Not monthly — weekly. Look for small, unfamiliar charges of a few dollars. These are "test transactions": attackers checking whether a card is live and unmonitored before attempting larger fraud. Report anything unfamiliar to your bank immediately and request card replacement if needed.
Note that Crunchyroll does not offer native two-factor authentication
This is genuinely frustrating for a platform with 17 million subscribers. Crunchyroll currently has no built-in 2FA option. This makes a strong, unique password your only account-level defence. All the more reason step 1 is non-negotiable. If Crunchyroll adds 2FA in future — enable it immediately.
If you watch Crunchyroll on public Wi-Fi — use a VPN
This breach originated at the server level, not from your connection — so a VPN wouldn't have prevented it. But with your email now confirmed as an active Crunchyroll subscriber and potentially in criminal hands, using public Wi-Fi without a VPN is a separate, additional risk. An unencrypted connection on a café or airport network exposes your session data in real time.
Protect your connection going forward
A VPN encrypts your traffic on public networks, preventing session hijacking and man-in-the-middle attacks. Given your email is now confirmed and circulating, adding a layer of connection security is a sensible precaution — particularly if you stream on the go.
GET NORDVPN → 30-day money-back guarantee · From $3.99/moHow to check if your account was in the breach
Go to haveibeenpwned.com and enter the email address you use for Crunchyroll. Have I Been Pwned has confirmed 1.2 million email addresses from this breach in its database, with more potentially to follow as additional data surfaces.
What HIBP will tell you is whether your email is confirmed in the breach. What it cannot tell you is whether your support ticket contents — your personal messages to Crunchyroll — are in a criminal's possession. Given the scale of what was extracted, assume they are if you have ever contacted Crunchyroll support.
The class action lawsuit — what it means for you
A class action lawsuit was filed in California federal court on March 24, 2026. The lawsuit alleges Crunchyroll failed to implement reasonable data security measures, violated Section 5 of the FTC Act and California's Consumer Records Act, and failed to adequately audit the security of its third-party vendor Telus.
The lawsuit seeks to cover all US users whose personally identifiable information was exposed. If you are a US resident with a Crunchyroll account, you may automatically be a member of the class — meaning you could be entitled to a settlement payout if the case succeeds, without needing to do anything now.
What a VPN does and doesn't protect against here
I want to be precise about this, because bad information on this point is rampant.
A VPN would not have prevented this breach. The attack happened at the server and support-system level — a malware infection on a third-party employee's workstation, not a network intercept of your connection. Your traffic encryption is irrelevant to how this breach occurred.
However, a VPN is still relevant to your overall security posture after this breach for two reasons. First, if your email is now confirmed as an active Crunchyroll subscriber and you use public Wi-Fi to stream, your session could be hijacked on an unsecured network — a VPN prevents this. Second, a VPN masks your real IP address, which was part of the stolen data. This limits the value of that IP data to attackers going forward.
What will actually protect you from the real consequences of this breach — phishing and credential stuffing — is a unique password on every account, and healthy scepticism toward any email that mentions Crunchyroll. Those two things are free and require no technical knowledge.
This breach isn't over — the worst is still coming
The data has been extracted. The ransom wasn't paid. That means the data will be sold or released into criminal networks if it hasn't been already. The phishing campaigns using personalised support ticket data haven't fully materialised yet. Change your passwords now, treat every Crunchyroll email as hostile, and check your statements weekly. That's the actual defence — not waiting for Crunchyroll to fix it.
Stream safely on the go
Both options have been independently tested and are recommended based on performance — not paid placement.