Over 420,000 User Accounts Affected In Weverse Data Breach

https://jazminemedia.com/wp-content/uploads/2026/09/Weverse.jpeg

HYBE’s global fandom platform Weverse has confirmed that data from more than 420,000 user accounts was leaked externally. While direct personal information such as names and contact details was not included, internal identifiers and payment-related information were part of the leaked data.

Weverse Company CEO Yang Joo Il issued a notice on September 6th, stating that following an external report about a security vulnerability, an internal review confirmed that some user information had been leaked.

Weverse Company received a report regarding the service’s security vulnerability from the Korea Internet & Security Agency (KISA) on September 3rd and immediately began an investigation. The probe determined that a total of 422,584 accounts, based on account ID, had their information leaked externally.

The leaked information included internal identifiers (unique numbers) used on the Weverse platform, along with payment methods, payment gateway (PG) company names, payment currency, purchase and cancellation amounts, transaction timestamps, and payment status.

However, the company clarified that personal information capable of directly identifying users, such as names and contact information, was not leaked. It also emphasized that the leaked information alone cannot be used to forge payments or attempt fraudulent transfers.

Following the incident, Weverse Company strengthened access controls for its payment API and took measures to prevent internal identifiers from being exposed externally. The company also filed an incident report with KISA on September 4th.

Weverse Company added that it plans to demand the recovery of leaked information from the external party who attempted the unauthorized access, while also pursuing legal responsibility.

Source: (A)

similar stories

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.