Find your next favorite work.

HYBE’s Weverse Leaks Data in 422,584 Cases, Payment Records Exposed but…

Late-night notice on the 6th reveals exposure of internal identification numbers and eight types of payment data

Weverse [Courtesy of Weverse Company. No redistribution or database use]
Weverse [Courtesy of Weverse Company. No redistribution or database use]

The security of Weverse, a global fan community platform, has been compromised. Weverse Company, a subsidiary of HYBE that operates the platform, has officially confirmed a large-scale data breach involving 422,584 records.

Yang Joo-il, CEO of Weverse Company, said in an official notice late on the 6th that the company discovered the leakage of some customer data while reviewing an external report of a security vulnerability. The incident exposed a critical security flaw at a company that has positioned itself as the world’s No. 1 fan platform.

Internal data that cannot identify users — but fan anxiety grows

The core data exposed was internal identification information. These are numbers generated randomly by the system when users register to distinguish them internally. The company stressed that the data did not include directly identifying sensitive information, such as names or contact details.

But it is too soon to take comfort. A large amount of payment-related data, classified as general information because it does not qualify as personal information, was also taken. The exposed items were as follows:

  • Purchase type (payment method) and purchase payment gateway

  • Currency and purchase and cancellation amounts

  • Purchase date and time, purchase status and refund date and time

Yang said, "The data in question alone would make it difficult for secondary damage, such as payment forgery or unauthorized transfers, to occur," adding, "We conducted a comprehensive review of externally exposed APIs (application programming interfaces) and strengthened access controls." He bowed his head in apology to fans concerned by the incident.

Legal action promised as rebuilding lost trust becomes key

Weverse Company is individually notifying those affected in accordance with applicable laws. It has also forcefully requested the return of the data from external actors who illegally accessed it through an abnormal hacking attack. The company said it intends to pursue legal accountability to the fullest extent over the damage caused by the incident.

Although the company has promised to prevent a recurrence by raising the sensitivity of its security monitoring to the highest level, a decline in trust appears inevitable for a platform that draws millions of fans from around the world. Thorough follow-up measures and a complete rebuilding of its security system are urgently needed.

×

댓글 (0)

아직 댓글이 없습니다. 첫 댓글을 작성해보세요!

댓글 작성