Hulu Data Breach
Hulu Streaming Service Breach (Salesforce, 2025): 94 Million Subscriber Email & Phone Records Exposed
Subscription streaming service.
Risk Interpretation
Exposure enables account takeover, phishing, and profiling based on entertainment behavior. Viewing and household data can also reveal routines and family structure.
Impact & Downstream Threats
The 2025 Hulu incident appears to have been part of the wider Salesforce-linked customer data theft and extortion wave rather than a uniquely documented Hulu-native platform compromise. Public breach reporting tied Hulu to a group of affected Salesforce customers whose data was allegedly exported and leaked by threat actors, which means the impact is best framed as downstream exposure of subscriber or business records through a third-party SaaS environment, creating risk for phishing, impersonat
- SIM swap attacks where phone numbers are present
- Targeted phishing campaigns using exposed email addresses
Threat Vectors
Breach Intelligence
Executive Summary
Streaming platform Hulu was caught up in a wave of attacks targeting Salesforce, a widely used customer relationship management service, in 2025. A threat actor calling itself "Scattered LAPSUS$ Hunters" claimed responsibility for exfiltrating data through this third-party platform and released a sample of the stolen records on October 3, 2025, announcing a full release of the dataset for October 10. The breach affected approximately 94.2 million customer records. The exposed data includes full names and email addresses, along with internal marketing and account metadata such as brand association, consent flags, and system timestamps. While the dataset does not include passwords or financial information, the combination of names and emails is enough to enable targeted phishing campaigns, account takeover attempts, and impersonation fraud. The breach pathway through a third-party vendor means Hulu customers may have been exposed without any direct compromise of Hulu's own systems. No regulatory action or formal breach notification process has been publicly confirmed as of the time of reporting. Affected individuals should be alert to unsolicited emails claiming to be from Hulu or Disney, treat any requests to verify account details or reset credentials with caution, and monitor their inboxes for phishing attempts that reference their streaming subscription.
About Hulu
Hulu is a U.S. subscription streaming platform focused on television, film, live TV, and general entertainment programming. It operates within Disney’s streaming ecosystem, but still functions as a distinct consumer brand built around on-demand viewing, ad-supported and premium subscription tiers, and bundled distribution with Disney+. �
Why They Hold Your Data
Streaming services collect user identity, subscription records, payment-adjacent data, device identifiers, viewing behavior, and household-linked account activity across entertainment platforms.
Recent Developments
Hulu’s recent trajectory has been defined by deeper integration into Disney’s broader streaming strategy. Disney announced in October 2025 that Hulu would become the global general entertainment brand on Disney+ internationally, replacing Star, and Hulu’s current 2026 release slate continues to be marketed through both Hulu and Hulu on Disney+ in the U.S. �
Data Points Exposed
Canonical Fields
email_address, full_name, phone_number
Dark Web Verification
- Dataset containing ~94.2M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: hulu-salesforce-2025
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of Hulu
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
