* Translated by AI

Starnews

Weverse, a fan platform, also hacked... "420,000 pieces of personal information leaked" [Official]

Published:

김나라

*This content was translated by AI.

/Photo=Weverse Company
/Photo=Weverse Company

Over 400,000 individuals' personal information was leaked from Weverse, the fan platform operated by HYBE subsidiary Weverse Company.

Yang Ju-il, CEO of Weverse Company, announced on the evening of the 6th via a notice on the Weverse Shop: "Recently, we received an external report regarding a security vulnerability in our service and immediately conducted an inspection. As a result, we confirmed that some customers' personal information was leaked."

According to their statement, they were contacted by the Korea Internet & Security Agency (KISA) on the 3rd, informing them that an external reporter had reported a security vulnerability in the Weverse service.

Following this, Weverse Company conducted its own inspection and emergency response, confirming that personal information of 422,584 accounts was leaked based on account IDs.

The leaked items include 'internal identification information' generated internally for user identification at the time of registration, as well as payment methods, purchase PG names, transaction types, purchase amounts and dates, cancellation amounts, purchase status, refund dates, and more.

Weverse Company stated: "As part of additional measures, we have strengthened access control over the payment information processing API and removed internal identifier information to prevent external exposure of data. On September 4, we reported the incident to KISA, including inspection results and response status."

They further explained: "The leaked internal identification information does not include personally identifiable details such as names or contact numbers; it consists only of identifiers used exclusively within Weverse Company's internal systems and cannot be used externally. Therefore, using only these data items makes it difficult to carry out payment fraud or unauthorized transfers."

Additionally, Weverse Company emphasized: "We have requested the return of relevant personal information from external actors who illegally accessed personal data through abnormal attacks, and we intend to hold them legally accountable for this incident."

Weverse Company added: "The company takes full responsibility for this incident. We will take responsible measures to alleviate customers' concerns and worries," bowing their heads while stating, "Once again, we sincerely apologize for the inconvenience caused to our customers."

They also promised: "Going forward, we will conduct a comprehensive investigation of all externally exposed APIs to strengthen access control and minimize information exposure. We will also enhance controls over deployment processes and increase the sensitivity of security monitoring to prevent similar incidents from recurring."

Weverse is a global fan communication platform that launched its service in 2019, marking its eighth year of operation this year. It has surpassed 150 million cumulative application downloads and 10 million monthly active users.

<© STARNEWS. All rights reserved. No reproduction or redistribution allowed.>

*This content was translated by AI.

Recommended News

Editor’s Pick

Latest in Entertainment