More than 420,000 personal data leaked from WEVERSE, the fan platform of HYBE.

On September 6, WEVERSE reported the leak of personal data. WEVERSE COMPANY, which operates WEVERSE, bowed down saying: “After receiving an external report regarding a vulnerability in the service’s security, we immediately proceeded with a verification and confirmed that certain personal data of our customers had leaked” and “We offer our most sincere apologies to the fans who trust and love WEVERSE for the great worries and concerns caused by this incident.”
On September 3, WEVERSE COMPANY was contacted by the Korea Internet & Security Agency (KISA), informing it that an external reporter had reported a vulnerability in the security of the WEVERSE service. From then on, WEVERSE COMPANY conducted an internal verification and an emergency response. Consequently, it was confirmed that 422,584 personal data, on the basis of account ID, had leaked.
The leaked details are:
▲ Personal data items: internal identification information (internal numerical value generated during user registration for internal identification)
▲ General information items (not corresponding to personal data): purchase type (payment method), purchase PG name, currency type (e.g. KRW), purchase amount, cancellation amount, date and time of purchase, purchase status (e.g. COMPLETE), date and time of refund (in the case where the purchase status is CANCELED).
WEVERSE COMPANY stated: “As part of additional measures, we strengthened access control for the payment information processing API and deleted the internal identifier information, thus strengthening security so that information is not exposed to the outside, and on the 4th, we proceeded to report the security breach incident to KISA, including the results of said verification and the response status.”
It continued by explaining: “The leaked internal identification information is not information directly identifying a person such as a name or contact details, but identification values used solely in WEVERSE COMPANY’s internal system and cannot be used externally. It is difficult for payment falsifications or fraudulent transfers to occur solely with these information items.”
WEVERSE COMPANY plans subsequently to review all APIs exposed to the outside to strengthen access control and minimize exposed information, while strengthening the control of the deployment process as well as the sensitivity of security monitoring. A request for recovery of the personal data concerned was made to the external actor who illegally accessed the personal data through an abnormal attack. WEVERSE COMPANY indicated: “We will hold the perpetrator legally responsible for these damages.”
Journalist: Shawn
Translator: Shawn
Source: Weverse