[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1amqpl5yv6oav":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":15,"seoTitleEn":28,"seoDescription":15,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda4882521e","funimation","Funimation Data Breach","funimation.com","2016-07-01T00:00:00.000Z","2017-02-20T00:43:26.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:51:54.652Z","Third party breach","",[],2491103,"known",null,"unknown","Critical",[23,24,25,26],"Dates of birth","Email addresses","Passwords","Usernames","\u003Cp>The Funimation data breach is an incident from July 2016 affecting user data in the context of anime publishing and online entertainment accounts. The verified scope is 2,491,103 unique accounts. The record included usernames, email addresses, dates of birth, and salted SHA-1 password hashes. When these fields are considered together, the risk is not limited to just an old streaming platform account; if the same email, username, or password was used on other accounts, attackers could try this information on different services.\u003C\u002Fp>\u003Cp>Since a Funimation account is a profile belonging to the anime and digital streaming community, the username and email match is meaningful in terms of social profile inference. The date of birth is permanent personal information that could be misused in some account recovery or age verification processes. Password hashes are not plain text passwords; however, SHA-1 is considered weak according to current password storage expectations. While the use of a salt makes the attack more difficult, the risk persists for short, common, or reused passwords.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data confirmed in this record are birth dates, email addresses, usernames, and passwords. The password field is in salted SHA-1 hash format. The email address can be used to contact the user and to attempt accounts on different services. The username can be matched with a person's different profiles in communities such as anime and streaming platforms. The birth date can make targeted messages more convincing and increase the guess risk in some old account recovery questions.\u003C\u002Fp>\u003Cp>Finding password hashes does not mean that attackers see the password directly. However, SHA-1 is an old hash method that can be calculated quickly; therefore, weak passwords can be cracked. If a user repeats the same password on their email account, social media profile, game account, streaming platforms, or shopping sites, the risk of account compromise increases. This issue is particularly important for users who have maintained the same password pattern over the years.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The number of verified unique accounts is 2,491,103. The incident date is recorded as July 1, 2016, and it is associated with the domain funimation.com. The data classes included in the record are username, email address, date of birth, and salted SHA-1 password hashes. This scope should be considered high priority in terms of account security and identity matching.\u003C\u002Fp>\u003Cp>In this record, the phone number, physical address, payment card, bank account, official identity document, browsing history, subscription payment detail, or private message content are not among the verified data fields. Users should not act as if payment data has been leaked; however, the presence of date of birth and password hash in the same record should not be underestimated. Risk communication should be based on verified fields.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people at highest risk are users who reuse the password they use on their Funimation account on other accounts as well. If the same password is used for email, gaming, social media, forum, shopping, or other streaming platforms, attackers may try the compromised passwords on these services. Even if old streaming platform accounts are forgotten, the password chosen at that time may still exist on other accounts.\u003C\u002Fp>\u003Cp>There is a risk of profile matching for people who use the same username across different anime, gaming, or social media communities. Along with the date of birth and email address, the username can make it easier to prepare fake account recovery, subscription renewal, membership campaign, or community notification messages that appear personalized. Therefore, users should pay attention not only to changing passwords but also to fake communication scenarios.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Any password that may have been used on a Funimation account should be changed immediately. If the same or a similar password exists on other accounts, they should all be changed to unique and long passwords. The email account should be prioritized for protection, because the password reset links for other accounts are sent to the inbox. If two-factor authentication is not enabled on the email account, it should be activated.\u003C\u002Fp>\u003Cp>Do not enter information via links in messages themed around old anime streaming accounts, subscription renewal, gift membership, account recovery, or community notifications. Verify the service's domain directly and confirm requests asking for one-time codes, passwords, or payment information through a separate channel. Review the login history and security notifications on other platforms where you use the same username.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The Funimation incident shows that entertainment and streaming platform accounts can also pose a lasting security risk. In the long term, users should use unique passwords for every streaming, gaming, forum, and social media account. Accounts that are no longer in use should be closed or protected with a strong password and two-factor authentication. Since repeating the same username across many platforms makes identity matching easier, using a different username or a separate email for critical accounts can be considered.\u003C\u002Fp>\u003Cp>From the perspective of platforms, strong password hash algorithms, a unique salt value for each user, data minimization, and clear incident reporting are basic security requirements. Although SHA-1 was commonly seen in the past, it is no longer considered sufficient for storing passwords. Persistent personal fields such as date of birth should not be kept if unnecessary; if they are kept, access and retention duration must be strictly managed.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If your email address appears in this record, check the passwords of Funimation or the streaming platform you used during the same period. If the same or similar passwords are used in other accounts, change all of them. Review the services where your date of birth is used in account recovery processes and enable two-factor authentication where possible. Check the privacy and security settings on other accounts with the same username.\u003C\u002Fp>\u003Cp>In the Funimation data breach, the verified fields are date of birth, email, username, and salted SHA-1 password hashes. Payment, address, or private content are not verified; however, when password hashes and date of birth are found together, the account security risk is high. The most accurate action is to stop password reuse, secure the email account strongly, verify fake subscription or account recovery messages through official channels, and prevent old entertainment accounts from creating risks on new accounts.\u003C\u002Fp>","Funimation Data Breach (2.5 Million Reported Records)","Funimation Data Breach. 2.5 Million reported records were reported. Reported data: Dates of birth, Email addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ffunimation_com.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Funimation","Anime Streaming","United States"]