Weverse Data Breach Exposes Over 400,000 User Accounts and Payment Histories

The incident was first brought to Weverse’s attention on September 3, when the Korea Internet & Security Agency relayed a report from an external informant about a vulnerability; Weverse then began an emergency investigation.
Weverse Company CEO Yang Ju-il publicly apologized to users, saying, “I sincerely apologize for causing great concern and worry to the fans who have trusted and cherished Weverse.”
Weverse said it would seek legal accountability for the damage caused by the incident, adding a potential legal-response track beyond its technical remediation and regulatory reporting.
The company said the exposed transaction details were not classified as personally identifiable information under current law, although the disclosure of users’ purchase histories could still draw criticism because it occurred without their consent.
Weverse, the global fan platform owned by HYBE, disclosed a data breach affecting 422,584 user accounts on September 3. Bitdefender reported that exposed data included internal user identifiers and transaction records like payment methods, purchase amounts, and order statuses. The company said the leaked information alone is unlikely to enable payment fraud, though users' purchasing histories were disclosed without consent.
Weverse CEO Yang Ju-il apologized publicly, stating, "I sincerely apologize for causing great concern and worry to the fans who have trusted and cherished Weverse." DataBreaches.Net noted that the company strengthened access controls, removed exposed identifiers, and reported the incident to South Korea's internet-security agency while notifying affected users.
South Korea's internet-security agency alerted Weverse to the vulnerability on September 3 after receiving a report from an external informant. KBizoom reported that Weverse then launched an emergency investigation to determine the scope of the breach. The company moved quickly to plug the security gap in its payment-processing API.
The breach exposed internal user identifiers and detailed transaction records for 422,584 accounts. Bitdefender confirmed that exposed payment data included payment methods, payment providers, currencies, purchase amounts, refund amounts, timestamps, and order statuses. The company stressed that names and contact details were not directly revealed by the internal identifiers.
Weverse argued that the exposed data alone cannot enable payment fraud or unauthorized transfers. However, JazmineMedia noted that the disclosure of users' purchase histories still raises privacy concerns because it occurred without user knowledge or consent, even if technically not classified as personally identifiable information under current South Korean law.
Weverse strengthened access controls for its payment-processing API and removed the exposed identifiers from circulation. The company reported the incident to South Korea's internet-security agency and notified all affected users of the breach. DataBreaches.Net reported that Weverse said it would pursue legal accountability for the damage caused.
Weverse is used by millions of K-pop fans worldwide to purchase merchandise, concert tickets, and exclusive content from their favorite artists. ArchyNetys reported that the breach affected payment records stored on the platform. While payment fraud seems unlikely based on what was exposed, fans' spending habits are now known to outside parties.
Publishers
18
Articles
1
Reach
19