Weverse payment API data leak (422,584 accounts)
HYBE's fan platform Weverse disclosed that a vulnerability in an externally exposed payment API leaked purchase, payment and refund records tied to 422,584 accounts, after South Korea's KISA alerted the company to the flaw.
- Victim
- Weverse Company (HYBE)
- records
- 422.6K
- users
- 422.6K
On 6 September 2026, Weverse Company, the HYBE subsidiary that runs the Weverse fan community and shopping platform used by K-pop fans worldwide, disclosed a data leak affecting 422,584 accounts. Company president Zooil Yang issued a formal apology to users.
The problem came to light on 3 September, when the Korea Internet & Security Agency (KISA) informed Weverse of a security vulnerability in the service that had been reported by an outside party. Weverse filed a breach report with KISA the next day and investigated with external security experts. The flaw sat in payment-related APIs that exposed internal user identifiers and transaction details.
What was exposed
The leaked fields were internal user identification numbers, purchase type, payment method and payment gateway name, currency, purchase and cancellation amounts, purchase dates and times, purchase status and refund dates. Weverse said names, contact details and card numbers were not part of the exposed data. The company tightened API access controls, removed internal identifiers from its payment APIs, notified affected customers individually and pledged to review all of its externally exposed APIs.
Context
It was the second data incident at Weverse in 2026, after an employee leaked personal information in January. It also followed a year of large South Korean consumer-platform breaches, including the compromise of 39.54 million accounts at streaming service Tving in June, which has kept regulators focused on the security of APIs behind popular apps.
Timeline
The Korea Internet & Security Agency (KISA) notifies Weverse of a vulnerability reported by an external party.
Weverse files a breach report with KISA.
Weverse Company president Zooil Yang publicly discloses the incident and apologizes to users.
Sources
- musicbusinessworldwide.comhttps://www.musicbusinessworldwide.com/hybes-weverse-confirms-data-leak-affecting-422584-accounts-including-payment-and-refund-details/
- soompi.comhttps://www.soompi.com/article/1868468wpp/weverse-notifies-users-of-data-leak
- digitalmusicnews.comhttps://www.digitalmusicnews.com/2026/09/08/weverse-data-breach-2026/