Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Hackers Claim Theft of 6.8 M Crunchyroll User Records via Compromised BPO Agent Credentials

Crunchyroll disclosed a breach after threat actors said they stole 6.8 M user records by compromising a Telus International support agent’s Okta SSO credentials. The attackers accessed Zendesk and other SaaS tools, exfiltrating support tickets that contain personal identifiers and limited credit‑card data, and demanded a $5 M ransom.

LiveThreat™ Intelligence · 📅 March 24, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

Hackers Claim Theft of 6.8 M Crunchyroll User Records via Compromised BPO Agent Credentials

What Happened – Threat actors say they breached Crunchyroll on 12 Mar 2026 by compromising the Okta SSO account of a support agent employed by Telus International, a third‑party BPO. Using malware‑derived credentials they accessed Zendesk, Google Workspace, Slack and other internal tools, exfiltrating roughly 8 M support‑ticket records (≈6.8 M unique email addresses) that contain names, IPs, locations and, in a few cases, partial credit‑card data. The attackers demanded a $5 M ransom but Crunchyroll has not responded.

Why It Matters for TPRM

  • Highlights the risk of credential theft from outsourced staff and the downstream impact on customer data.
  • Shows how a single compromised SSO account can cascade across multiple SaaS services.
  • Demonstrates the need for continuous monitoring of third‑party access and rapid revocation capabilities.

Who Is Affected – Media & entertainment streaming platforms; BPO/outsourced support providers; any organization exposing customer‑service data via SaaS ticketing systems.

Recommended Actions

  • Conduct an immediate audit of all third‑party SSO integrations and enforce MFA for every privileged account.
  • Review and limit the scope of access granted to BPO personnel (principle of least privilege).
  • Verify that all compromised credentials have been revoked and monitor for anomalous activity across linked SaaS tools.
  • Assess the exposed support‑ticket data for PII and notify affected users per regulatory requirements.

Technical Notes – Attack vector: stolen Okta credentials via malware on a BPO agent’s workstation; lateral movement through Zendesk, Google Workspace, Slack, Mixpanel, etc. No public evidence of a vulnerability in Crunchyroll’s own code. Data exfiltrated includes email, name, IP, geographic info, ticket content; limited credit‑card details appear only where users voluntarily shared them. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →