×
  • remind me tomorrow
  • remind me next week
  • never remind me
Subscribe to the ANN Newsletter • Wake up every Sunday to a curated list of ANN's most interesting posts of the week. read more

Forum - View topic
NEWS: Crunchyroll Confirms Some Login Credentials Were Posted on Social Media; States There is 'No E




Note: this is the discussion thread for this article

Anime News Network Forum Index -> Site-related -> Talkback
View previous topic :: View next topic  
Author Message
pikabot



Joined: 19 Nov 2014
Posts: 176
PostPosted: Fri Jan 24, 2025 10:26 pm Reply with quote
Plaintext credentials on Twitter is not generally how data breaches come to light; generally speaking what you see is someone trying to sell an archive of encrypted data they’d exfiltrated. And if Crunchyroll was actually storing credentials in plain text, it would be a massive security fuckup that you need to actively go out of your way to do in this day and age. Stranger things have happened but so far evidence suggests that this is a list of people who got phished rather than a data breach.
Back to top
View user's profile Send private message
Kougeru



Joined: 13 May 2008
Posts: 5612
PostPosted: Fri Jan 24, 2025 11:13 pm Reply with quote
pikabot wrote:
Plaintext credentials on Twitter is not generally how data breaches come to light; generally speaking what you see is someone trying to sell an archive of encrypted data they’d exfiltrated. And if Crunchyroll was actually storing credentials in plain text, it would be a massive security fuckup that you need to actively go out of your way to do in this day and age. Stranger things have happened but so far evidence suggests that this is a list of people who got phished rather than a data breach.


99% of "hacks" reported on social media are just from people getting phished so this is likely
Back to top
View user's profile Send private message AIM Address My Anime My Manga
mdo7



Joined: 23 May 2007
Posts: 6720
Location: Katy, Texas, USA
PostPosted: Sat Jan 25, 2025 1:39 am Reply with quote
Kougeru wrote:
99% of "hacks" reported on social media are just from people getting phished so this is likely


Luckily, I'm not one of the victims although I will admit I had my cases of suspicious users trying to befriend and talk to me on Instagram, but because I was too smart to tell these phishing accounts/profiles couldn't answer any of my basic questions, I blocked them.
Back to top
View user's profile Send private message Visit poster's website My Anime My Manga
sharkticon



Joined: 19 Jul 2011
Posts: 34
PostPosted: Sat Jan 25, 2025 1:46 am Reply with quote
Gonna post here what I posted a few other places.

Most of the creds, according to haveibeenpwned are from 2025 stealer malware logs. The Poster seems to be a general grifter, with the follow up links being affiliate links to get rich quick schemes. He also tells a few people in the comments who claimed the creds were theirs "this is what happens when you don't pay."

This appears to have been a scammer and grifter who got way more attention than he expected. None of the evidence points to it coming from Crunchyroll.
Back to top
View user's profile Send private message
RupanSansei



Joined: 20 Sep 2024
Posts: 168
PostPosted: Sat Jan 25, 2025 1:57 am Reply with quote
glad i never subbed to crunchyroll as they always seemed sketchy as all hell especially considering they used be a pirate site. i literally got a permaban on their reddit from the mods due to sharing the old piracy era logo
Back to top
View user's profile Send private message
NieR



Joined: 29 Apr 2012
Posts: 223
PostPosted: Sat Jan 25, 2025 6:03 am Reply with quote
Dang. I have a free 30-day Premium trial I won in a Twitter giveaway [alongside Nintendo Switch digital game code for Samurai Jack: Battle Through Time] back in 2020, and if the trial requires that I enter in my bank card information to use it, I think I may have to let the trial code expire in August...

The Samurai Jack game was an awesome gaming experience and I'm glad I have it both digitally and physically in my video game collection.
Back to top
View user's profile Send private message
Ataru



Joined: 04 Jan 2002
Posts: 2332
Location: Missouri (Strikeman)
PostPosted: Sat Jan 25, 2025 7:45 am Reply with quote
Change your password, even if you don't think you are on that list. Use a password manager, like KeePass or BitWardan, and make sure it's random so there is little chance it will be shared with another site.

I'm amazed there is no 2FA on Crunchyroll or the store. That's pretty basic security these days.
Back to top
View user's profile Send private message Send e-mail MSN Messenger My Anime My Manga
NickCMedia



Joined: 23 Nov 2023
Posts: 16
PostPosted: Sat Jan 25, 2025 8:18 am Reply with quote
Regardless, I changed my password. I think we should all change our passwords at least once every six months, just in case.
Back to top
View user's profile Send private message
Farhanawesome



Joined: 31 Dec 2020
Posts: 247
PostPosted: Sat Jan 25, 2025 8:56 am Reply with quote
RupanSansei wrote:
glad i never subbed to crunchyroll as they always seemed sketchy as all hell especially considering they used be a pirate site. i literally got a permaban on their reddit from the mods due to sharing the old piracy era logo


So are you saying that you want Crunchyroll to be bankrupt or something ?
Back to top
View user's profile Send private message
XSp



Joined: 23 May 2014
Posts: 284
PostPosted: Sat Jan 25, 2025 9:49 am Reply with quote
Ataru wrote:
I'm amazed there is no 2FA on Crunchyroll or the store. That's pretty basic security these days.


Agreed. Though just to give a shout out... I think they might have a pretty limited version of it if you include your cellphone number on your settings. It's SMS or Messaging based only, which is the worst type of 2FA basically, but it's... something.
They need to start using at least ToTP though.
Back to top
View user's profile Send private message
Top Gun



Joined: 28 Sep 2007
Posts: 4860
PostPosted: Sat Jan 25, 2025 10:42 am Reply with quote
NickCMedia wrote:
Regardless, I changed my password. I think we should all change our passwords at least once every six months, just in case.

No offense, but no one has time to do that.
Back to top
View user's profile Send private message
mdo7



Joined: 23 May 2007
Posts: 6720
Location: Katy, Texas, USA
PostPosted: Sat Jan 25, 2025 10:46 am Reply with quote
Ataru wrote:
I'm amazed there is no 2FA on Crunchyroll or the store. That's pretty basic security these days.


XSp wrote:
Agreed. Though just to give a shout out... I think they might have a pretty limited version of it if you include your cellphone number on your settings. It's SMS or Messaging based only, which is the worst type of 2FA basically, but it's... something.
They need to start using at least ToTP though.


Yeah, I'm kind of surprised that Crunchyroll has not created or implemented a 2/multi-factor authentication like most websites would have (even MyAnimeList/MAL has 2FA). So I'm not sure why they didn't implement that given that CR users are using credit card to pay their streaming subscription. That's really baffling. Confused
Back to top
View user's profile Send private message Visit poster's website My Anime My Manga
el_morris



Joined: 09 May 2018
Posts: 293
Location: Tijuana, México
PostPosted: Sat Jan 25, 2025 12:26 pm Reply with quote
I changed my password about two months ago (something I do regularly) but changed it anyways regardless if my data was compromised or not.
Quote:
several streaming services

Like which ones? I haven't seen news on leaks of other services recently.
Back to top
View user's profile Send private message
chronos02



Joined: 25 Feb 2009
Posts: 273
PostPosted: Sat Jan 25, 2025 3:33 pm Reply with quote
pikabot wrote:
Plaintext credentials on Twitter is not generally how data breaches come to light; generally speaking what you see is someone trying to sell an archive of encrypted data they’d exfiltrated. And if Crunchyroll was actually storing credentials in plain text, it would be a massive security fuckup that you need to actively go out of your way to do in this day and age. Stranger things have happened but so far evidence suggests that this is a list of people who got phished rather than a data breach.


This does appear to be the most likely case, and CR has provided a pretty sound reply about what the users should do, which is honestly quite rare, especially the "diversify" part. However, changing passwords regularly is not a good idea, as pointed out in many security articles. Regular password changes can, in fact, make your account less secure, and increases the risk of account loss under some circumstances , so it's not recommended to change passwords regularly, and only to do so when the circumstances make it necessary, such as when there are suspicions of a security breach, such as this case.
What is very recommended, perhaps absolutely necessary, is to use completely different passwords for every account from the same and different services, otherwise, 1 security breach will compromise all or many of your other accounts. In order to accomplish this, however, you will need a password manager (unless you have godly memory). I personally have no recommendations, but after using a few and getting backstabbed by these services, I simply went with google's password manager, as well as a local manager, which is a hassle, hence google's one as well (but this is also bad, since if the google account gets compromised, everything gets compromised, so I do not recommend this... it's a single point of failure after all).
What CR did not do, however, is ask its users to change passwords given the suspicion of a data breach, which is not great, they could at least have recommended they do this even if they are confident no data was leaked, more so when they encourage "regular" password changes (even if that, as said, is not a great idea).

Still, I highly encourage people to check actual studies on the best practices to keep your account(s) secure, what I said might not even apply anymore due to the constant changes and evolution of IT, and as a simple user, what I said should obviously be taken with a grain of salt.

Happy watching I guess.
Back to top
View user's profile Send private message
Mamo-chan



Joined: 09 Jun 2003
Posts: 79
PostPosted: Sat Jan 25, 2025 9:31 pm Reply with quote
I always change my password every year or so. I should increase that to every 6 months.
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Reply to topic    Anime News Network Forum Index -> Site-related -> Talkback All times are GMT - 5 Hours
Page 1 of 1

 


Powered by phpBB © 2001, 2005 phpBB Group