Personal information involving approximately 420,000 cases has been leaked from Weverse, a fan platform operated by Weverse Company, a subsidiary of HYBE.
Yang Joo-il, CEO of Weverse Company, stated in an official notice released on the night of September 6, "We recently received an external report regarding a vulnerability in our service security and immediately conducted an inspection. As a result, we confirmed that some of our customers' personal information was leaked. We sincerely apologize to the fans who trust and cherish Weverse for causing great concern and worry due to this incident."
According to Weverse Company, they were notified by the Korea Internet & Security Agency (KISA) on September 3 that an external informant had reported a security vulnerability in the Weverse service. Following internal inspections and emergency response measures, they confirmed that 422,584 pieces of personal information had been leaked.
The leaked personal information item is internal identification data generated internally to identify users upon registration.
CEO Yang drew a line by stating, "The leaked internal identification information is not information that directly identifies individuals, such as names or contact details, but rather identification values used exclusively within Weverse Company's internal systems, which cannot be used externally." He explained, "It is difficult for payment forgery or fraudulent transfers to occur using only these specific information items."
Yang stated, "We have proceeded with the process of individually notifying customers subject to this leak in accordance with the standards set by relevant laws. As part of additional measures, we have strengthened access control for the payment information processing API and removed internal identifier information to prevent data exposure to the outside, thereby enhancing security. On September 4, we filed a security breach report with KISA, including the inspection results and response status."
He added, "Moving forward, we will conduct a comprehensive investigation of externally exposed APIs to strengthen access controls and minimize exposed information, while enhancing controls on deployment processes and the sensitivity of security monitoring to do our utmost to prevent similar incidents from recurring."
He also stated, "We have requested the recovery of the relevant personal information from the external actor who illegally accessed the personal information through abnormal attacks, and we plan to hold them legally responsible for this damage."
Yang bowed his head repeatedly, saying, "The company takes its responsibility for this matter very seriously, and we will take responsible measures to alleviate our customers' worries and concerns. We once again deeply apologize for causing inconvenience to our customers."
(Photo: Yonhap News / Reported by Kang Kyung-yoon, SBS Entertainment News)
※
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.