Weverse confirms leak of 422,584 personal data records

연합뉴스

| yna@yna.co.kr 2026-09-07 09:39:00

▲ Corporate logo of Weverse Company

 

 

SEOUL, Sept. 7 (Yonhap) -- About 420,000 records of personal information have been leaked from Weverse, HYBE's fan platform, the company operating the service said Monday.

 

Weverse Company CEO Yang Ju-il said in a notice posted late Sunday that 422,584 records of personal information, based on account IDs, had been leaked.

 

"We immediately conducted an inspection after receiving an external report about a recent security vulnerability, and confirmed that some customers' personal information had been leaked," Yang said.

 

"I sincerely apologize to all the fans who trust and cherish Weverse for causing such great concern and worry," he added.

 

According to the notice, the leaked information consists of internal identification data, or internal numerical values generated when users sign up for the service to identify them within the company's systems.

 

Yang stressed, however, that "the leaked internal identification information is not data that directly identifies individuals, such as names or contact information, but identification values used only within Weverse Company's internal systems and cannot be used externally." He added that it would be difficult to forge payments or make unauthorized transfers using the information alone.

 

Other information leaked from Weverse included purchase type, or payment method; payment gateway provider; currency type; purchase amount; canceled amount; purchase date and time; purchase status; and refund date and time. The company said these are general information items and do not constitute personal information.

 

Yang said, "Customers affected by the leak have been separately notified in accordance with procedures required under relevant laws."

 

He added that the company "will conduct a comprehensive inspection of APIs exposed externally and strengthen access controls and the sensitivity of security monitoring to prevent similar incidents from happening again."

 

Yang also said the company has requested that the external party that illegally accessed the personal information through an abnormal attack return the affected data.

 

"We plan to hold the party legally accountable for the damage caused by this incident," he said.


[ⓒ K-VIBE. 무단전재-재배포 금지]