Crunchyroll·Technology / SaaS·
Attackers demanded $5 million.
Crunchyroll said the information was primarily customer-service ticket data following a third-party vendor incident; attackers claimed access through an Okta account. The exact technical root cause is not established in the attached record.
Report freshness and timeline
- Reported incident date
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Entry path: Telus Digital
- Consequence
- Reported: Attackers demanded $5 million.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Crunchyroll
- Industry
- Technology / SaaS
- Disclosed
- Event date
- Third party
- Telus Digital
- Affected asset
- Zendesk support system
- Product / vendor
- Zendesk
- Data involved
- Personal data
- Reported impact
- Extortion demand
- Attached evidence
- 8 independent domains · 8 sources
2)Evidence-backed incident path
- 01
Third party
Telus Digital
ConfidenceSecondaryExact excerpt
E1“an employee at Telus Digital”
techcrunch.com · Mar 24 - 02
Affected product
Zendesk
ConfidenceSecondaryExact excerpt
E2“Crunchyroll’s Zendesk support system”
techcrunch.com · Mar 24 - 03
Reached
Zendesk support system
ConfidenceSecondaryExact excerpt
E3“gained access to Crunchyroll’s Zendesk support system”
techcrunch.com · Mar 24 - 04
Observed
Attackers demanded $5 million.
ConfidenceProbableExact excerpt
E4“demanded $5 million from Crunchyroll”
tech.yahoo.com · Mar 30
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The exact technical root cause
- No ransom payment is established
- That a Defence review would have prevented this incident
4)Relevance to your product
One durable credential can carry yesterday's access into today's product.
This pattern applies when…
- Products that use outsourced customer-support platforms and vendor identities.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Technology / SaaS
- 2 incident threads
- 1 incident threads
- 5 incident threads
- 2 incident threads
- 13 incident threads
- 5 incident threads
- 18 incident threads
- 16 incident threads
- 16 incident threads
- 16 incident threads
- 7 incident threads
- 29 incident threads
- Same incident family
- 56 Supply chain / third party
- Confirmed share
- 40% 52 confirmed · 78 reported
- Display family
- Supply chain Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Technology / SaaS in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
Also relevant: Identity and session testing
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
8 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.
- E4tech.yahoo.comCrunchyroll Confirms Customer Data Breach Linked to Third-Party VendorOther public report · Mar 30 · CitedOther public reportCited
Exact excerpt
“demanded $5 million from Crunchyroll”
- E1, E2, E3techcrunch.comCrunchyroll confirms data breach after hacker claims ...Established press · Mar 24 · CitedEstablished pressCited
Exact excerpt
“Crunchyroll’s Zendesk support system”
- S3bleepingcomputer.comCrunchyroll probes breach after hacker claims to steal 6.8M users' dataEstablished press · Mar 23 · AttachedEstablished pressAttached
Exact excerpt
“6.8 million unique email addresses”
Show all 8 sourcesShow the first six sources
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.