{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account"},"incident":{"slug":"2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account","title":"Crunchyroll support tickets stolen via compromised BPO agent SSO account","date":"2026-03-12","date_precision":"day","year":2026,"victim_org":"Crunchyroll","sector":"Media & Entertainment","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"On 12 March 2026 an attacker used a compromised Okta single sign-on account belonging to a support agent working for outsourcer Telus International to reach Crunchyroll's Zendesk instance. The attacker claimed roughly eight million support ticket records, about 6.8 million with unique email addresses, containing names, credentials, email and IP addresses, locations and ticket contents. Access was revoked after 24 hours. A $5 million extortion demand went unanswered.","how_it_worked":"The weak point was not Crunchyroll's own workforce but a third-party contact centre agent with standing access to the streaming service's ticketing system. The attacker said malware on the agent's machine captured their credentials, then used the resulting Okta session to authenticate into Zendesk as a legitimate support operator. Because helpdesk agents routinely open and read large numbers of tickets, bulk retrieval did not stand out immediately, and roughly 24 hours passed before access was cut. Some payment card details were exposed only where customers had typed them into tickets.","lessons":"Outsourced agent identities need the same phishing-resistant MFA and device-health enforcement as employees, plus per-agent ticket access rate limits so no single account can enumerate the whole queue.","confidence":"Reported","sources":[{"title":"Crunchyroll probes breach after hacker claims to steal 6.8M users' data","url":"https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/amp/","publisher":"BleepingComputer"},{"title":"1.2 million Crunchyroll users confirmed impacted by data breach","url":"https://cyberinsider.com/1-2-million-crunchyroll-users-confirmed-impacted-by-data-breach/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-crunchyroll-support-tickets-stolen-via-compromised-bpo-agent-sso-account"}}