▲ Weverse Company Personal Information Leak Notice
It has been confirmed that personal information amounting to approximately 420,000 cases was leaked from Weverse, the fan platform operated by HYBE.
Weverse Company, the operator of Weverse, announced through a notice in the name of CEO Yang Joo-il on the night of the 6th that personal information corresponding to 422,584 account IDs had been leaked.
CEO Yang apologized, stating that after receiving an external tip regarding a service security vulnerability and conducting an inspection, it was confirmed that some customers' personal information had been leaked.
According to the notice, the leaked personal information is internal identification information, which is an internal numerical value generated for user identification upon user registration.
CEO Yang explained, "The leaked internal identification information is not information that directly identifies individuals, such as names or contact information, but rather an identification value used only within the Weverse Company internal system and cannot be used externally," adding, "It is difficult for payment forgery or fraudulent transfers to occur using only these information items."
In addition to the internal identification information, other items were also leaked, including purchase types (payment methods), payment gateway (PG) names, currency formats, purchase amounts, cancellation amounts, purchase dates and times, purchase statuses, and refund dates and times.
These types of information are classified as general information items and do not fall under personal information.
Accordingly, Weverse strengthened security by tightening access controls on the payment information processing API (application programming interface) and removing internal identifiers to prevent information exposure to the outside, and reported the inspection results and response status to KISA (Korea Internet & Security Agency) on the 4th, CEO Yang stated.
He also announced that procedures were underway to separately notify customers affected by the leak in accordance with standards set by relevant laws and regulations.
Regarding future improvements and additional measures, he explained, "We will conduct a comprehensive investigation of external exposure APIs (application programming interfaces) to strengthen access control and minimize exposed information, and we will heighten the sensitivity of security monitoring in the deployment process to do our utmost to prevent similar incidents from recurring."
Furthermore, he stated, "We have requested the recovery of the relevant personal information from the external actor who illegally accessed the personal information through an abnormal attack," and added, "We plan to hold them legally responsible for this damage."
(Photo provided by Weverse Company, Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News