"It Is Difficult to Forge Payments with Internal Identification Data"

Weverse Logo

Weverse Logo

View original image

On the fan platform Weverse, operated by HYBE subsidiary Weverse Company, the personal data of 422,584 accounts (based on account ID) was leaked.


Weverse Company, which manages Weverse, announced on the 6th through a statement signed by CEO Yang Juil, "After inspecting for security vulnerabilities in our service, we have confirmed that some user personal information was leaked."


After receiving a notification on the 3rd from the Korea Internet & Security Agency (KISA) that an external informant had reported a security vulnerability in the Weverse service, the company immediately launched its own inspection and emergency response. On the 4th, the company submitted an incident report to KISA detailing the inspection results and response status.


The leaked personal information was internal identification information generated by the company to identify users during registration. Weverse Company explained, "This is not information that can directly identify a person, like a name or contact number, but an identification value used only within our internal system." The company added that it would be difficult for payment forgery or unauthorized transfers to occur with just this information.


Other exposed items included purchase type (payment method), purchase PG (payment gateway) name, currency form, purchase amount and time, cancellation amount, purchase status, and refund time. Weverse Company stated that these purchase-related items do not fall under the category of personal information.


After confirming the incident, the company strengthened access controls on the payment information processing application programming interface (API) and removed internal identification information from the data transmitted externally. Users whose personal information was leaked were individually notified of the incident in accordance with relevant laws and regulations.


The company is also conducting a full inspection of all externally exposed APIs. It plans to further strengthen access controls and reduce the amount of information exposed. Controls over the distribution process and security monitoring will also be reinforced. HYBE stated, "We will do our utmost to prevent similar incidents from recurring."


Weverse Company has also requested the unauthorized external actors who accessed the personal information to return the related data. The Weverse team declared, "We expect to hold those responsible for this incident legally accountable."


CEO Yang stated, "We deeply apologize to our fans who have trusted and supported Weverse for the great concern and worry caused by this incident," adding, "We take full responsibility for this matter and will take all necessary steps to address your concerns and restore your trust."



Weverse is a fan community platform that launched its service in 2019. It has recorded more than 150 million cumulative application (app) downloads and over 10 million monthly active users (MAU).


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing