HYBE-operated fan platform Weverse disclosed unauthorized exposure affecting 422,584 user accounts after the Korea Internet & Security Agency (KISA) alerted it to a service vulnerability. Exposed information included Weverse-only internal identifiers and transaction-related data; the company said the identifiers cannot be used outside its platform.
Weverse reported the incident to KISA, notified affected users, and tightened access controls on its payment-information API while removing exposed internal identifier data. The company said it will review externally exposed APIs and deployment procedures and pursue legal action against the external actor it holds responsible.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Weverse submitted a breach-incident report to KISA containing its inspection findings and response status.
The Korea Internet & Security Agency (KISA) notified Weverse of a security vulnerability in its service that had been reported by an external party. Weverse began an investigation with external cybersecurity experts.
Following the incident, Weverse strengthened access controls for its payment-information API, removed internal identifier information from the affected API exposure, and separately notified affected customers.
Weverse's investigation confirmed that confidential information associated with 422,584 accounts was exposed, including internal user identifiers and transaction-related information. The company said the internal identifiers could not directly identify individuals or be used outside the platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.