Weverse Company has reported a data leak involving 422,584 cases counted by account ID on its global fan platform.
The HYBE-affiliated company disclosed the incident in an official notice on Sept. 6, saying it confirmed that information belonging to some customers had been exposed while investigating a security vulnerability.
According to the company, the Korea Internet & Security Agency notified it on Sept. 3 that an external researcher had reported a vulnerability in the Weverse service. Weverse Company conducted an internal review and emergency response before filing an incident report with KISA on Sept. 4.
The personal information involved was an internal numerical identifier generated when a user registers for the service. The company’s notice did not list names, contact details, passwords or card numbers among the exposed data.
Purchase-related records were also exposed, including payment method, payment gateway provider, currency, purchase and cancellation amounts, transaction time and status, and refund time. Weverse Company classified these items as general information rather than personal information.
The company said its internal identifiers cannot be used outside its systems and that the exposed data alone would be unlikely to enable payment fraud or unauthorized transfers. That assessment was made by Weverse Company; no findings from a regulatory investigation have been released.
Weverse Company said it strengthened access controls for its payment-processing application programming interface and removed internal identifiers from externally exposed information. It also separately notified affected customers.
The company plans to inspect all externally accessible APIs, reduce the amount of exposed information and tighten controls over software deployment and security monitoring. It has requested that the external party return the accessed data and said it intends to pursue legal action.
The notice did not specify how long the vulnerability had existed, the precise method used to access the information or whether the exposed data had been used elsewhere.
In a separate incident disclosed in January, Weverse Company acknowledged that an employee had shared personal information related to fan events in a private group chat.
SayArt.net ReaA JUNG queen7203@gmail.com
Internal identifiers and purchase records exposed through a service vulnerabilityCourtesy of Weverse
Weverse Company has reported a data leak involving 422,584 cases counted by account ID on its global fan platform.
The HYBE-affiliated company disclosed the incident in an official notice on Sept. 6, saying it confirmed that information belonging to some customers had been exposed while investigating a security vulnerability.
According to the company, the Korea Internet & Security Agency notified it on Sept. 3 that an external researcher had reported a vulnerability in the Weverse service. Weverse Company conducted an internal review and emergency response before filing an incident report with KISA on Sept. 4.
The personal information involved was an internal numerical identifier generated when a user registers for the service. The company’s notice did not list names, contact details, passwords or card numbers among the exposed data.
Purchase-related records were also exposed, including payment method, payment gateway provider, currency, purchase and cancellation amounts, transaction time and status, and refund time. Weverse Company classified these items as general information rather than personal information.
The company said its internal identifiers cannot be used outside its systems and that the exposed data alone would be unlikely to enable payment fraud or unauthorized transfers. That assessment was made by Weverse Company; no findings from a regulatory investigation have been released.
Weverse Company said it strengthened access controls for its payment-processing application programming interface and removed internal identifiers from externally exposed information. It also separately notified affected customers.
The company plans to inspect all externally accessible APIs, reduce the amount of exposed information and tighten controls over software deployment and security monitoring. It has requested that the external party return the accessed data and said it intends to pursue legal action.
The notice did not specify how long the vulnerability had existed, the precise method used to access the information or whether the exposed data had been used elsewhere.
In a separate incident disclosed in January, Weverse Company acknowledged that an employee had shared personal information related to fan events in a private group chat.
Warning: Trying to access array offset on value of type bool in /home/sayart/public_html/_libs/smarty/templates_c/103e99f6d7d08ee6b6541efd32c0ef2f33076acc_0.file.news_3t_view.tpl.php on line 56
Warning: Trying to access array offset on value of type bool in /home/sayart/public_html/_libs/smarty/templates_c/103e99f6d7d08ee6b6541efd32c0ef2f33076acc_0.file.news_3t_view.tpl.php on line 59