6.8 million people just had their personal information leaked out of Crunchyroll, and if you’re one of them — or your kid is — the most dangerous part of this breach hasn’t happened yet. It happens in the next 60 to 90 days.
Related: Two more data breach settlements just opened — $13.7 million you can claim now
Related (April 2026): If you receive a settlement payment from this or any data breach, it counts as taxable income — something most people don’t realize until the IRS sends a penalty notice.
Here’s what’s on the record. A class action lawsuit filed March 24, 2026 in the U.S. District Court for the Northern District of California (Agress v. Crunchyroll, Case No. 3:26-cv-02553) lays out the breach. On March 12, an employee at Crunchyroll’s India-based outsourcing partner Telus ran malware on their system, giving an outside attacker access to Crunchyroll’s support systems for roughly 24 hours. Crunchyroll didn’t disclose the breach publicly until ten days later, on March 22. The lawsuit alleges that 6.8 million unique email addresses and 8 million support ticket records were exposed — including names, usernames, email addresses, IP addresses, approximate location data, and the full text of customer support conversations.
The Daily Money Brief — Free, at 10 AM
Money you may be owed, scams to dodge, and the fine print decoded — the consumer money news that affects your wallet, every weekday.
Some of those support conversations contain partial payment card details (last four digits, expiration dates) that customers had voluntarily shared when resolving billing issues. Enough for a determined criminal to start building a picture of you.
If you’ve ever had a Crunchyroll account — or your teenager does — you need to understand what happens next.
The Part Most Breach Stories Skip
Every breach story ends the same way. There’s an announcement. The company offers a year of free credit monitoring. You maybe sign up, maybe don’t. The story fades from the news cycle in a week.
That’s not when the damage happens. The damage happens 60 to 180 days later, when the stolen data gets sorted, packaged, and sold on criminal forums. The people who buy that data aren’t random hackers — they’re businesses. They run phishing operations and fraud schemes at industrial scale, and they have workflows for turning your leaked email and name into money.
Here’s the pattern I’ve watched unfold every single time for 20 years.
Weeks 1-4 (the quiet period). The attackers are organizing the data, cross-referencing it against other breaches, and building richer profiles. You get the breach notification email and the “free credit monitoring” offer. Everything seems fine.
Weeks 4-12 (phishing starts). You get an email that looks like it’s from Crunchyroll, or from your bank, or from a streaming service you actually use. It references something specific enough that you think it’s real — because the attackers have your support ticket history, they know which shows you watched and which billing issues you had. The email asks you to “verify your account” or “update your payment method.”
Weeks 12-24 (the expensive wave). If they got enough payment information, unauthorized charges start showing up. If they didn’t, the attackers pivot to account takeovers — trying the leaked email and common password patterns against Gmail, Amazon, PayPal, and crypto exchanges. One successful login can unlock the rest of your digital life.
The credit monitoring Crunchyroll will offer you covers one piece of this — the credit report piece. It does not cover the phishing wave. It does not cover account takeovers. It does not cover someone using your name and address to apply for services or to impersonate you to a customer service rep. You have to cover those yourself. And if someone has already used leaked data to open accounts in your name, go straight to my crisis guide on accounts opened in your name and collectors calling.
What Makes This Breach Different
Most data breaches leak structured data — just names and emails. This one leaked unstructured data too: the actual text of support conversations. That matters because it gives attackers context. They know your complaints, your account history, your tone when you write, the kinds of questions you ask. They can construct a phishing email that sounds exactly like something Crunchyroll would genuinely send you, because in a sense they’ve already read Crunchyroll’s side of the conversation.
That’s a much higher quality of scam than the usual “your package could not be delivered” garbage. It’s harder to spot. And the audience — millions of anime fans, heavily skewed toward younger users in their teens and twenties — is the demographic with the least experience recognizing a sophisticated phishing attempt.
If you’re a parent and your kid has a Crunchyroll account, this is the part you need to read with them.
What To Do Right Now — Before the Phishing Wave Hits
1. Change your Crunchyroll password today. Make it unique to Crunchyroll. Do not reuse passwords you use anywhere else. If you’ve been using the same password on multiple sites, change all of them — because when a password leaks from one service, criminals try it on every other service you might have an account on.
2. Turn on two-factor authentication on every account tied to your email. Not just Crunchyroll — your main email itself, your bank, Amazon, PayPal, Venmo, any crypto wallet, any service that holds a payment method. The email address that leaked is the recovery address for everything else you own. Lock it down.
3. Freeze your credit at all three bureaus — Experian, TransUnion, Equifax. This is free. It takes about 10 minutes per bureau. A frozen credit file means no one can open a new credit account in your name, even if they have your full information. You can unfreeze temporarily when you actually apply for credit. (This same step is critical for the Fidelity data breach settlement — up to $5,000 if you file by July 27.) This is the single highest-value defensive move you can make after any breach.
4. Watch your bank and credit card statements weekly for the next six months. Not monthly — weekly. Small “test” charges of a few dollars are the attackers checking whether a card works before they run up real charges.
5. Assume every email about “your Crunchyroll account” for the next year is a scam. If Crunchyroll genuinely needs you to do something, go to their website directly by typing the URL. Do not click links in emails. Do not reply with information. Do not call phone numbers from emails. The phishing wave is coming, and the emails will be convincing.
6. For parents: have the conversation with your kid. Younger users are more likely to trust a professional-looking email from a service they actually use. Walk through the family rule: no clicking, no information, no calling back — ever — without running it by you first.
Why the Class Action Matters — But Don’t Count On It
The lawsuit is real, and it may eventually produce a settlement that pays out a few dollars per person along with some expanded identity monitoring. Those things are worth having. But the timeline from lawsuit filing to actual check is typically two to four years. If you wait for the class action to protect you, the scam wave will have already happened.
The class action is the cleanup. What you do in the next 30 days is the prevention.
Save your paperwork, too. If you’re notified that you’re an affected user, save that notification. If you later suffer identity theft, financial fraud, or phishing-induced losses, that notification is your evidence trail that the breach contributed to the harm.
This is what I’d tell my own grandkids if they had a Crunchyroll account — and the ones who watch anime do. It’s my informed take, not legal advice. Only you know your own situation and what the right defensive posture is. Take this as input. Nobody — not me, not a streaming service, not an attacker — gets to make your security decisions for you.
If you know anyone — especially a younger family member — with a Crunchyroll account, forward this post. The difference between getting it before the phishing wave and after is usually the difference between an inconvenience and a nightmare.
The same lesson applies to the Spectrum/Charter data breach — when a breach leaks contact information rather than Social Security numbers, the real threat is targeted phishing, not identity theft.
Dealing With Debt? Understanding your options is the first step. See how all your debt relief options compare — including ones most sites won’t tell you about. The Find Your Path quiz gives a recommendation based on your actual numbers, and the Scam-O-Meter checks any company’s complaint history before you sign. Federal Reserve research shows bankruptcy filers recover faster than those who don’t file.