Observed Signal · Mar 24, 2026 · Data Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Crunchyroll Confirms Customer Support Data Breach
Crunchyroll is investigating a security incident after attackers claimed to have accessed a support agent’s account at a third‑party vendor and downloaded roughly eight million support tickets, which the attacker says correspond to about 6.8 million unique users. The intruders reportedly used malware on a Telus International employee’s machine to harvest credentials and accessed systems used for customer support and collaboration (Zendesk, Google Workspace Mail, Jiro and Slack). Attackers shared screenshots with Bleeping Computer and demanded $5 million; Crunchyroll declined to pay and says it is working with security experts. The company states the information appears limited to support‑ticket data and that it has found no evidence so far of broader access to Crunchyroll’s core systems. The breach may include nicknames, email and IP addresses, ticket contents and, in a small number of cases according to the attacker, credit card details.
A publisher/streaming service breach potentially exposes millions of user records and highlights third‑party vendor and SSO vulnerabilities—relevant to privacy, identity management, and risk for media owners and their advertising/partner ecosystems.
Track Zendesk Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Attackers claim to have downloaded about 8 million support tickets tied to Crunchyroll customer support systems.
- Crunchyroll says the tickets correspond to approximately 6.8 million distinct users.
- Adversaries reportedly gained access via malware on a Telus International support employee’s computer and reused credentials to access Zendesk, Google Workspace Mail, Jiro and Slack.
- Attackers demanded a $5 million ransom; Crunchyroll refused and is investigating with external security experts.
- Crunchyroll states it has found no evidence so far of broader access to its core systems and believes exposed data is mainly from support tickets; attackers claim a small number of tickets contained credit card details.
Connected Companies & Entities
3 Entities mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Crunchyroll Support-Ticket Data Breach via Partner
A hacker group claims to have stolen more than eight million Crunchyroll support tickets—reportedly representing 6.8 million unique users—after compromising the account of a customer‑support agent employed by Telus International. According to screenshots shared with Bleeping Computer, attackers installed malware on the agent’s computer, captured login credentials and accessed systems used for Crunchyroll support (Zendesk, Google Workspace Mail, Jiro and Slack). The attackers demanded $5 million; Crunchyroll declined. Crunchyroll says it is working with security experts, believes the exposed information is primarily support‑ticket data tied to a partner incident, and has found no evidence of broader access to its systems. Impacted ticket contents may include usernames, email and IP addresses, coarse location data, ticket text and, in a small number of cases, credit‑card details.
Tenga: Hacker Stole Customer Information
Japanese sex-toys maker Tenga notified customers that an unauthorized party accessed a professional email account of one of its employees, exposing the inbox contents and potentially customer names, email addresses and historical correspondence — which may include order details or customer-service inquiries. TechCrunch obtained the notification email, which said the intruder also sent spam to the compromised account’s contacts. A forensic review communicated to TechCrunch found the breach affected approximately 600 people in the United States; it is unclear whether customers outside the U.S. were impacted. Tenga said it reset the employee’s credentials and enabled multi-factor authentication across its systems, and recommended customers change passwords and watch for suspicious emails. The company noted it has shipped over 162 million products worldwide. The report was first published Feb. 13 and updated with a Tenga spokesperson’s comment.
Klue hack exposes customer data across cybersecurity firms
Market intelligence provider Klue disclosed a cyberattack that allowed hackers to exfiltrate customer data from connected cloud systems. Klue said intruders gained access on June 12 using a “compromised legacy credential” tied to an integration tool that links customers’ cloud data (such as Salesforce) to Klue. The cybercrime group Icarus claimed responsibility and threatened to publish the stolen data if a ransom is not paid. Multiple Klue customers — including Gong, Jamf, HackerOne, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, Insurity and Huntress — have confirmed data theft of business contact and some account information. Klue engaged CrowdStrike for incident response and disconnected integrations to block further access. The company has not disclosed how many customers were affected or how the credentials were obtained.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
