Exclusive: Musinsa exposed personal data of seller representatives after 29CM customer breach
Translated from Korean and summarized by DistantNews. Read the original for the full story.
At a glance
- Musinsa found that personal information belonging to representatives of brands selling through Musinsa and 29CM had also been exposed during its investigation into a previous 29CM customer-data breach.
- The leaked information included usernames, names, email addresses, mobile phone numbers, departments and job titles, but Musinsa has not disclosed the number of affected people or accounts.
- The company reset affected accounts, blocked the attackerโs access and asked sellers to reset passwords and re-register two-factor authentication.
Musinsa has confirmed that the personal information of representatives from brands selling through its platforms was exposed, adding another layer to a data breach that had already affected 29CM customers.
The company discovered the additional leak on the first day of this month while investigating the earlier incident. Musinsa had previously said that 29CM exposed 138,841 customer names, along with 21,011 records containing names, email addresses, mobile phone numbers and delivery information.
Names, departments, job titles and contact details are sensitive information that can identify individuals specifically, and there are concerns that it could be used for spear-phishing attacks targeting particular people or companies, or for settlement fraud.
The latest breach occurred on a dedicated webpage that representatives of Musinsa and 29CM seller brands use to manage and operate their platforms. The exposed information included usernames, names, email addresses, mobile phone numbers, departments and job titles. The specific information varied by person. Musinsa has not disclosed the precise scale of the breach or the number of exposed accounts.
Especially because many of the platformโs sellers are small brands with fewer than five employees, they may find it difficult to recover from financial fraud or security incidents, which could damage their operations.
An advertising-industry source said the seller representativesโ information could carry risks comparable to those involving ordinary customer data. โNames, departments, job titles and contact details are sensitive information that can identify individuals specifically, and there are concerns that it could be used for spear-phishing attacks targeting particular people or companies, or for settlement fraud,โ the source said. The source added that many platform sellers are small brands with fewer than five employees, making it harder to recover from financial fraud or security incidents.
Musinsa reportedly reset the exposed accounts and blocked the attackerโs access after discovering the incident. It asked seller companies to reset passwords and re-register one-time-password authentication. The company also warned them to be cautious of contacts impersonating platform managers and urging them to sign contracts or make payments. A Musinsa representative said the company had informed those affected after confirming the additional exposure, but could not discuss the scale or details while cooperating with relevant authorities.
Additional exposure was confirmed during the investigation into the earlier personal-information breach, and we notified those affected.
Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.