News

HYBE Subsidiary Weverse Suffers Data Leak Affecting 420,000 Users, CEO Issues Apology

HYBE Subsidiary Weverse Suffers Data Leak Affecting 420,000 Users, CEO Issues Apology
Weverse (Photo=Getty Images Korea)

Fan platform Weverse, operated by HYBE subsidiary Weverse Company, has experienced a personal data leak affecting approximately 420,000 users.

Weverse Company CEO Yang Joo-il released an official statement on the night of the 6th, stating, "We recently received an external report regarding service security vulnerabilities and immediately conducted an inspection, as a result of which we confirmed that some of our customers' personal information was leaked. We sincerely apologize to the fans who trust and cherish Weverse for causing great concern and worry due to this incident."

According to Weverse Company, they were notified by the Korea Internet & Security Agency (KISA) on the 3rd that an external whistleblower had reported security vulnerabilities in the Weverse service. Following self-inspections and emergency responses, they confirmed that 422,584 cases of personal information had been leaked.

The leaked personal information items consist of internal identification information generated internally to identify users when they sign up.

CEO Yang drew a line by explaining, "The leaked internal identification information is not information that directly identifies individuals, such as names or contact information, but rather identification values used only within the Weverse Company internal system and cannot be used externally." He added, "It is difficult for payment forgery or fraudulent transfers to occur using only these information items."

Yang stated, "We have proceeded with the process of separately notifying customers subject to this leak in accordance with the standards set by relevant laws. As part of additional measures, we have strengthened access control for payment processing APIs and removed internal identifier information to prevent information from being exposed externally. On the 4th, we filed an infringement report with KISA containing the inspection results and response status."

He continued, "Moving forward, we will conduct a full investigation of externally exposed APIs, strengthen access control, minimize exposed information, and enhance control over deployment processes and the sensitivity of security monitoring to do our utmost to prevent similar incidents from recurring."

He also stated, "We have requested the recovery of the relevant personal information from external actors who illegally accessed personal information through abnormal attacks, and we plan to hold them legally responsible for this damage."

CEO Yang bowed his head repeatedly, saying, "The company takes its responsibility for this matter heavily, and we will take responsible measures to resolve our customers' worries and concerns. We deeply apologize once again for the inconvenience caused to our customers."

(SBS Entertainment News | Kang Kyung-youn)
Copyright Ⓒ SBS. All rights reserved. 무단 전재, 재배포 및 AI학습 이용 금지

Most Read