HYBE's Weverse Hit by Another Data Breach... Information Security Investment Drops Despite Return to Profit
Second Security Breach This Year After 2021 Incident
"Not Subject to Punitive Fines, but May Be Considered as an Aggravating Factor"
Amid a second personal data leak occurring this year alone on HYBE's global fandom platform Weverse, it has been revealed that Weverse’s investment in information security decreased by 10% last year.
According to the platform industry on September 9, Weverse Company—the operator of Weverse—announced via an official notice on September 6 that a total of 422,584 pieces of personal information were leaked due to a security vulnerability within the service. The breached information included internal member identifiers, payment methods, payment gateway (PG) information, currency types, as well as payment and refund amounts.
The company explained, “Internal identification information cannot be used externally, so incidents such as payment forgery or unauthorized transfers are difficult to occur,” in an attempt to reassure users. The company also announced additional measures, such as strengthening API access controls. However, user complaints and criticism about the global platform’s apparent lack of security awareness are mounting, as this is the second data breach this year—following a case in January when an internal employee leaked personal details of event winners without authorization.
Launched in 2019, Weverse boasts a total of 150 million cumulative downloads and, as of the second quarter of this year, 14.43 million monthly active users (MAU). Serving as a major communications channel for fans worldwide, the company posted its first profit in its history last year, with revenue of 299,662,260,000 won and an operating profit of 2,020,660,000 won.
However, after steadily increasing since 2021, Weverse’s investment in information security dropped for the first time last year. According to the Korea Internet & Security Agency (KISA) Information Security Disclosure Portal, Weverse Company invested 2,834,710,000 won in information security last year, representing a 10.3% decrease from the previous year. Investment in information technology also fell by 4.6% to 37,873,200,000 won. As a result, the ratio of information security investment to information technology investment shrank from 8.0% to 7.5%.
An industry expert commented, “Investment in information security often spikes briefly after a leak but is one of the first things to be cut when things are quiet. The truly frightening situation is when a company gets hacked but does not even know it. Companies need to continue investing to build robust defenses.”
Weverse Company will not be subject to the punitive fine (up to 10% of revenue) stipulated by the revised Personal Information Protection Act, which comes into effect on September 11. The amended law applies only to incidents discovered after the effective date. However, authorities are expected to consider the fact that this is not the first such incident this year during their deliberation on sanctions.
A Personal Information Protection Commission official stated, “To prevent confusion from retroactive application, the effective date has been specified in the supplementary provisions. However, repeated incidents of the same nature can be considered an aggravating factor when evaluating the scale or seriousness of a breach.”
Hot Picks Today
[Breaking] President Lee: "My term of office is clearly limited by the Constitution"
- "I Have Canceled All My Tickets to Japan"... Unprecedented Turmoil Among Travelers
- Switching from Grandeur to EV Saves 2 Million Won Annually...165 km on a 10-Minute Fast Charge
- Not a Raucous Party, but a Crowd Gathers... Unconventional Reading Groups Spread Worldwide with Sold-Out Events
- Chairman Seungho Choi of the Samsung Electronics Union Denies Personal Gain in 300 Million Won Contract with Father-in-Law's Company
In 2021, Weverse Company also suffered a data leak incident in which the names, email addresses, gender, mobile phone numbers, and membership numbers of 137 members were exposed due to a system error. At the time, it received a corrective order and a fine of 7,000,000 won from the Personal Information Protection Commission.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.