Weverse, Hive's global fandom platform, has suffered a data breach exposing personal information from more than 422,000 accounts.
Weverse Company, which operates the platform, said Sunday night that CEO Yang Ju-il issued a public notice disclosing that personal data tied to a total of 422,584 account IDs had been leaked.
The company launched an emergency investigation after receiving an external tip about a security vulnerability in the service, and confirmed during that review that actual user data had been compromised.
In the notice, Yang apologized to users. "I sincerely apologize for causing great concern and worry to the fans who have trusted and cherished Weverse," he said.
The information exposed in the breach consists of "internal identification data" assigned to users at account registration — unique numerical values generated within Weverse Company's systems to identify individual users.
Yang sought to limit alarm over the scope of the damage, saying the leaked data "is not information that can directly identify an individual, such as a name or contact details, but rather an identifier used exclusively within internal systems and cannot be utilized externally." He added that the risk of secondary financial harm — such as fraudulent payments or unauthorized transfers — from the exposed data alone was low.
However, it also emerged that payment-related transaction records were exposed alongside the internal identifiers. The leaked data includes payment method, payment gateway provider name, transaction currency, payment and cancellation or refund dates and amounts, and order status. Weverse Company said such transaction details do not constitute personally identifiable information under current law. The company is nonetheless likely to face criticism given that fans' purchase histories and payment patterns were exposed without their consent.
Weverse Company said it has completed individual notifications to affected users as required by law. As preventive measures, it announced a comprehensive audit of externally exposed application programming interfaces and said it would significantly strengthen access controls and security monitoring.
Yang said the company had notified the external attacker who illegally accessed user data through an "abnormal attack" to immediately return the information. "We intend to hold the perpetrator strictly accountable, both civilly and criminally," he added.
shee@heraldcorp.com
