
Crunchyroll Faces Urgent Security Breach Claims
The anime community is buzzing with concern following recent allegations that Crunchyroll, a major player in anime streaming, may be grappling with a significant security breach. An independent cyber security watchdog, International Cyber Digest, brought these claims to light via X (formerly Twitter) on Sunday, sparking a swift response from the company.
Unpacking the Allegations: What Happened?
According to the International Cyber Digest account, the potential security incident originated within Crunchyroll’s ticketing system, which is reportedly outsourced to a partner in India, Telus. The claims suggest that a malicious actor leveraged malware on this outsourcing partner's system to illicitly access and steal a substantial 100 GB of customer analytics data.
This alleged data haul is said to include highly sensitive and identifiable customer information. The list of compromised data points is alarming, potentially encompassing IP addresses, email addresses, and even crucial credit card details. The culprit reportedly informed the International Cyber Digest that this breach occurred on March 12, adding a specific timeline to the worrying reports.
Crunchyroll's Official Response
In response to these serious allegations, ANN reached out to Crunchyroll. A spokesperson for the anime streaming giant provided a concise statement: "We are aware of recent claims and are currently working closely with leading cyber security experts to investigate the matter." While this statement acknowledges the claims and signals an active investigation, the details surrounding the breach remain under wraps from Crunchyroll's side as the situation unfolds. Fans are eagerly awaiting further official communication and updates regarding the extent of the alleged compromise and the steps being taken to secure user data.
Broader Context: Layoffs and Lingering Privacy Concerns
This potential security incident surfaces amidst a period of considerable change for Crunchyroll. The company recently underwent a significant restructuring, resulting in a number of employee layoffs and a redistribution of roles. Crunchyroll attributed these changes to a shift in its e-commerce strategy, rather than cost-cutting measures.
Adding to its challenges, Crunchyroll is currently facing a consumer digital privacy class action complaint. This lawsuit alleges that the company violated the Video Privacy Protection Act (VPPA) by knowingly disclosing users' personally identifiable information related to their video viewing activity on its application to a third-party marketing and analytics company, Braze Inc.
Furthermore, this isn't the first time Crunchyroll has faced such legal scrutiny over privacy. A 2022 class action lawsuit made similar allegations of VPPA violation, specifically concerning the use of Facebook Pixel to share user video viewing information with Facebook. That lawsuit concluded with Crunchyroll settling for US$16 million in September 2023 and agreeing to modify its tracking technologies to prevent non-compliant disclosure of user viewing data. These past and ongoing privacy battles underscore the critical importance of robust data security and transparent user consent, especially for platforms handling vast amounts of personal information.
What This Means for Anime Fans
For the millions of anime fans who rely on Crunchyroll for their daily dose of content, these allegations are a serious concern. The potential exposure of personal and financial information highlights the ever-present risks in the digital landscape. While Crunchyroll is investigating, users might consider reviewing their account security and remaining vigilant for any unusual activity.
Crunchyroll operates as an independently run joint venture between U.S.-based Sony Pictures Entertainment and Japan's Aniplex, both ultimately subsidiaries of Tokyo-based Sony Group. The company was acquired by Sony's Funimation Global Group from AT&T in 2021 for US$1.175 billion.
As Crunchyroll continues its investigation, the anime community will be closely watching for updates. This article will be updated as soon as more details emerge from Crunchyroll or the ongoing cybersecurity investigation.