DistantNews
Support us
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Technology

HYBE Fan Platform Weverse Hit Again, Exposing Data on 422,584 Accounts

From Hankyoreh · () Korean

Translated from Korean and summarized by DistantNews. Read the original for the full story.

At a glance

News Official statement Outcome reported
  • Weverse said a security vulnerability exposed information linked to 422,584 account IDs, including internal identifiers and purchase details.
  • The company said the vulnerability involved an externally exposed payment-information API and that it had strengthened access controls and reported the incident to KISA.
  • The breach follows earlier Weverse privacy incidents, including a 2021 system error and the disclosure of user information by an employee in June.

HYBE subsidiary Weverse Company said personal information linked to 422,584 account IDs leaked from its fan platform after an external tip exposed a security vulnerability.

In a notice issued on the night of Sept. 6 under Chief Executive Yang Joo-ilโ€™s name, the company said, โ€œWe received an external report about a service security vulnerability and, after conducting an inspection, confirmed that some customersโ€™ personal information had been leaked.โ€ The Korea Internet and Security Agency told Weverse Company on Sept. 3 that an outside reporter had identified the flaw. The company then carried out its own investigation.

The leaked data included internal identifiers created by Weverse to identify users within its system. It also included payment methods, payment gateway names, currencies, purchase and cancellation amounts, purchase times, purchase status and refund times. The company said the internal identifiers could not directly identify people in the way names or phone numbers can, and that the data alone would make payment fraud or unauthorized transfers difficult.

The incident involved a security weakness in an externally exposed API that processed payment information. Weverse Company said it strengthened the APIโ€™s access controls and removed the internal identifiers. It reported the breach to KISA on Sept. 4 and said it separately notified affected users as required by law. The company also plans to inspect all externally exposed APIs, limit the information they expose, tighten controls over service deployment and improve security monitoring. It said it had asked the outside party who illegally accessed the personal information to return it and would pursue legal responsibility.

This is not Weverseโ€™s first privacy incident. In 2021, the Personal Information Protection Commission found that a system error allowed users to log in to other peopleโ€™s accounts, exposing the names, email addresses, genders, mobile phone numbers and membership numbers of 137 users. The company received a corrective order and a 7 million won fine. In June, an employee handling fan events was found to have shared applicantsโ€™ names and birth years in a private KakaoTalk group and sent a list containing the names, birth dates and phone numbers of 30 winners of another event outside the company. Weverse hosts artists from HYBE, including BTS, Seventeen and Enhypen, as well as artists from other agencies.

We received an external report about a service security vulnerability and, after conducting an inspection, confirmed that some customersโ€™ personal information had been leaked.

· Yang Joo-ilThe Weverse Company chief executive announced the breach in a company notice.
About this summary

Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.