Weverse Says Leak Hit 422,584 Accounts in Payment Data Breach

HYBE’s superfan platform says an external vulnerability exposed internal identifiers and transaction details, but not names, contact information or card numbers.

HYBE’s Weverse has confirmed a data leak affecting 422,584 accounts, with exposed information including internal identification data and transaction records tied to payments and refunds.

What Weverse says was exposed

The disclosure came in a notice issued Sunday, September 6, by Zooil Yang, president of Weverse Company, the HYBE subsidiary that runs the platform. Weverse said the figure was calculated based on account ID units.

The company said one leaked item was personal information: an internal identification value, described as a unique numerical code generated for user identification at registration. The rest of the exposed data, according to Weverse, was not classified as personal information. That list included purchase type, payment gateway name, currency type, purchase amount, cancellation amount, purchase date and time, purchase status, and refund date and time for canceled purchases.

Weverse said names, contact details and card numbers were not among the items listed in the breach.

How the breach surfaced

According to the company, the Korea Internet & Security Agency contacted it on September 3 after an external reporter flagged a security vulnerability in the service. Weverse said it then carried out an internal inspection and emergency response, and filed a breach incident report with KISA on September 4.

Yang said the company “immediately conducted an inspection” after receiving the report and confirmed that some customers’ personal information had been leaked. He apologized to fans for the incident and said Weverse would pursue legal responsibility for the damage caused.

Weverse said it has tightened access controls on the API that processes payment information and removed internal identifier information from it to prevent external exposure. It also said it notified affected customers under the criteria set out in relevant laws and regulations.

The company said the leaked internal identification information does not directly identify a person and cannot be used externally. It also said it is unlikely that payment forgery or unauthorized fund transfers could occur based on the exposed data alone.

Questions still unanswered

Weverse did not identify the cause of the vulnerability, how long the data was exposed, or how much of it has been recovered. The notice also does not say whether the external reporter who flagged the issue and the external actor who allegedly accessed the data are the same party. It is also unclear whether the affected accounts include users outside South Korea.

The company said it will investigate all externally exposed APIs, tighten access control, reduce the information those APIs expose, strengthen deployment controls and increase the sensitivity of its security monitoring. Yang said Weverse has requested the retrieval of the relevant personal information from the external actor who illegally accessed it through an abnormal attack.

This is the second data incident Weverse Company has confirmed this year. On January 5, the company said an internal employee had unlawfully leaked another person’s personal information and attempted to use it for private purposes. Weverse said at the time that it removed the employee from duties, referred the matter to its disciplinary committee and filed a criminal complaint.

The breach lands as Weverse continues to scale. HYBE’s most recent earnings release said the platform reached a record 14.43 million monthly active users in the second quarter of 2026. Total payment volume rose 12% quarter-over-quarter, while average revenue per paying user climbed 24%. Weverse also passed 200 artist communities in the quarter after adding P-pop acts BINI and SB19.

HYBE reported record quarterly revenue of KRW 1.45 trillion, or about $967 million, in the same period, driven by the BTS WORLD TOUR ‘ARIRANG.’ Yang took over as president of Weverse Company on June 1, succeeding Joon Choi. Universal Music Group invested in Weverse in 2024 as part of a 10-year deal that also gave UMG exclusive distribution rights to HYBE’s music.

The disclosure follows a larger breach at Tving, the South Korean video streaming service operated by CJ ENM. That incident was reported on June 1 after an attacker used a stolen developer access key to reach internal systems. A government-civilian investigation announced by the Ministry of Science and ICT on September 3 found that data from 39.54 million Tving accounts had been compromised, along with 361 technical assets, including source code. South Korea’s Personal Information Protection Commission has yet to determine the final scope of that breach or any penalties.

The ministry’s findings were released the same day KISA contacted Weverse Company.

South Korea’s platform security problem is getting harder to ignore

For HYBE, the issue is not just reputational. Weverse sits at the center of a business built on direct fan relationships, payments and membership data. That makes platform security a core operating issue, not a back-office one. When transaction details are exposed, even without card numbers or names, the trust hit lands fast.

Weverse’s response now has to do two things at once: contain the breach and convince users that the platform’s payment infrastructure is being hardened. For a service that has become a major revenue engine inside HYBE, that is not a side story. It is the story.

Related Stories