Crunchyroll’s data breach is ‘limited to customer service ticket data,’ representatives say


4

The anime streaming platform says that the information hacked is limited

On March 23, reports emerged online about a significant data breach affecting Crunchyroll, the leading anime streaming platform. The information was first shared by International Cyber Digest on X and by BleepingComputer. The latter was allegedly contacted by the hacker responsible for the breach, who claimed to have breached Crunchyroll on March 12 through malware infecting the computer of an employee of an outsourcing company who has access to Crunchyroll support tickets. The threat actors claimed to have used malware to infect the agent’s computer and gain access to their credentials. The hacker claims they downloaded eight million support ticket records, which included almost seven million unique email addresses.

Polygon reached out to Crunchyroll representatives on March 23. A spokesperson shared the following statement: “We are aware of recent claims and are currently working closely with leading cybersecurity experts to investigate the matter.”

On March 24, Crunchyroll shared a further statement and update on the incident:

“Our investigation is ongoing, and we continue to work with leading cybersecurity experts. At this time, we believe that the information is primarily limited to customer service ticket data following an incident with a third-party vendor. We have not identified evidence of ongoing access to systems in relation to these claims. We are continuing to monitor the situation closely.”

While the first part of the statement confirms the claims made by the hacker, Crunchyroll’s reassurance that there was no ongoing access to systems should comfort its users a bit. This also confirms BleepingComputer’s assessment that the support tickets shown by the hacker only contain general information like users’ name, login name, email address, IP address, general geographic location, and the contents of the support tickets. Moreover, “while other reports on the incident claim that credit card information was exposed, BleepingComputer has confirmed that credit card details were exposed only when the customer shared them in the support ticket. For the most part, this included only basic information, such as the last four digits or expiration dates, and only a few contained full card numbers, according to the threat actor.”

.



Source link

  • Related Posts

    Star Wars Jedi director's single-player Dungeons & Dragons game cancelled less than a year after it was announced

    That was quick. Hasbro has reportedly cancelled the single-player Dungeons & Dragons action-adventure being made by Star Wars Jedi director Stig Asmussen, less than a year after it was announced.…

    Milky Subway is an overlooked sci-fi anime coming to Netflix on June 1

    Netflix’s newly released summer anime slate has something for every anime enthusiast. You can choose to explore titles like My Dress-Up Darling, Shangri-La Frontier, or Assassination Classroom before their respective…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Star Wars Jedi director's single-player Dungeons & Dragons game cancelled less than a year after it was announced

    Star Wars Jedi director's single-player Dungeons & Dragons game cancelled less than a year after it was announced

    Advocates warn Quebec deportations are separating families, urge federal intervention

    Advocates warn Quebec deportations are separating families, urge federal intervention

    “You Have 30 Seconds”: United Pilot’s FBI Warning Over Passenger’s Wi-Fi Hotspot Name

    “You Have 30 Seconds”: United Pilot’s FBI Warning Over Passenger’s Wi-Fi Hotspot Name

    FirstFT: US strikes Iranian missile sites

    https://www.cbc.ca/news/canada/edmonton/aish-adap-alberta-disability-income-9.7165516

    Oticon Medical Introduces Ponto™ Instant, Expanding Non-Surgical Choice with Instant HearBand and Instant SoundConnector