Last Update: 08/01/2026 at 2:00 PM EST

Crunchyroll Vendor Support Breach

Coverage from BleepingComputer, Tech Insider, and others

Articles

5

Active Days

124

The Topic

Crunchyroll Vendor Support Breach topic image

Crunchyroll is investigating a breach tied to a third-party support vendor, with attackers claiming access to help-desk systems, support tickets, and related user data through compromised SSO credentials. The main pattern is vendor-mediated access turning into privacy exposure through weak identity controls and support workflows.

First Article: 03/23/26

Latest Article: 07/24/26

Summary

  • The strongest signal is a vendor-mediated support breach, not a core platform compromise.
  • Attackers allegedly used a compromised Okta SSO account for a support agent to reach Zendesk and related tools.
  • Reported exposure concentrated on support-ticket data, including email addresses, login details, IP addresses, locations, and ticket contents.
  • The incident highlights help-desk and business-process-outsourcing risk as an access path into customer data.
  • Extortion claims and contested access-duration figures add some uncertainty, but the privacy exposure pattern is consistent.
  • The topic is currently narrow and coherent, with little evidence of broader fragmentation beyond the exact scope of data accessed.

History

This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.

Featured

Timeline: 124 Days

Mar 23Apr 13May 11Jun 1Jun 29Jul 20

Additional Articles

⭐⭐⭐⭐⭐

Guptadeepak / Deepak Gupta07-24-2026
A phished vendor support agent compromised Adobe systems and extracted 13 million customer records plus unpublished HackerOne vulnerability reports, bypassing alerting.

⭐⭐⭐

Techzine Global / Mels Dees03-25-2026
HackerOne reported a Navia vendor breach in the United States between December 2025 and January 2026 that exposed personal data, including US Social Security numbers, for 287 employees.