DEFENCE / RADAR

Public snapshot

Crunchyroll·Technology / SaaS·

Attackers demanded $5 million.

Crunchyroll said the information was primarily customer-service ticket data following a third-party vendor incident; attackers claimed access through an Okta account. The exact technical root cause is not established in the attached record.

Report freshness and timeline

Reported incident date
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Entry path: Telus Digital
Consequence
Reported: Attackers demanded $5 million.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Crunchyroll
Industry
Technology / SaaS
Disclosed
Event date
Third party
Telus Digital
Affected asset
Zendesk support system
Product / vendor
Zendesk
Data involved
Personal data
Reported impact
Extortion demand
Attached evidence
8 independent domains · 8 sources

2)Evidence-backed incident path

  1. 01

    Third party

    Telus Digital

    ConfidenceSecondary
    Exact excerpt

    an employee at Telus Digital

    techcrunch.com · Mar 24
    E1
  2. 02

    Affected product

    Zendesk

    ConfidenceSecondary
    Exact excerpt

    Crunchyroll’s Zendesk support system

    techcrunch.com · Mar 24
    E2
  3. 03

    Reached

    Zendesk support system

    ConfidenceSecondary
    Exact excerpt

    gained access to Crunchyroll’s Zendesk support system

    techcrunch.com · Mar 24
    E3
  4. 04

    Observed

    Attackers demanded $5 million.

    ConfidenceProbable
    Exact excerpt

    demanded $5 million from Crunchyroll

    tech.yahoo.com · Mar 30
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • No ransom payment is established
  • That a Defence review would have prevented this incident

4)Relevance to your product

One durable credential can carry yesterday's access into today's product.

This pattern applies when…

  • Products that use outsourced customer-support platforms and vendor identities.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Technology / SaaS

130 incident threads in the 365-day public record
  1. 2 incident threads
  2. 1 incident threads
  3. 5 incident threads
  4. 2 incident threads
  5. 13 incident threads
  6. 5 incident threads
  7. 18 incident threads
  8. 16 incident threads
  9. 16 incident threads
  10. 16 incident threads
  11. 7 incident threads
  12. 29 incident threads
Same incident family
56
Supply chain / third party
Confirmed share
40%
52 confirmed · 78 reported
Display family
Supply chain
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Technology / SaaS in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

Also relevant: Identity and session testing

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

8 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E4
    tech.yahoo.comCrunchyroll Confirms Customer Data Breach Linked to Third-Party VendorOther public report · Mar 30 · Cited
    Other public reportCited
    Exact excerpt
    demanded $5 million from Crunchyroll
  2. E1, E2, E3
    techcrunch.comCrunchyroll confirms data breach after hacker claims ...Established press · Mar 24 · Cited
    Established pressCited
    Exact excerpt
    Crunchyroll’s Zendesk support system
  3. S3
    bleepingcomputer.comCrunchyroll probes breach after hacker claims to steal 6.8M users' dataEstablished press · Mar 23 · Attached
    Established pressAttached
    Exact excerpt
    6.8 million unique email addresses
  4. S4
    anonhaven.comCrunchyroll Data Breach via Telus Digital OutsourcerOther public report · Mar 23 · Attached
    Other public reportAttached
  5. S5
    tecnobits.comCrunchyroll data breach: Be careful if it affects youOther public report · Mar 24 · Attached
    Other public reportAttached
  6. S6
    zyberwalls.comCrunchyroll Supply Chain Breach: Telus Access Compromise ExplainedOther public report · Mar 24 · Attached
    Other public reportAttached
Show all 8 sourcesShow the first six sources
  1. S7
    techrepublic.comNearly 7M Email Addresses Exposed in Crunchyroll Third-Party BreachEstablished press · Mar 25 · Attached
    Established pressAttached
  2. S8
    geekfeed.netCrunchyroll probes breach after hacker claims to steal 6.8M users’ data - Geek FeedOther public report · Mar 25 · Attached
    Other public reportAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →