HYBE’s superfan platform Weverse has confirmed that data from 422,584 accounts was leaked, a figure the company said was calculated based on account ID units.
The leak was disclosed in a notice issued on Sunday (September 6) by Zooil Yang, President of Weverse Company, the HYBE subsidiary that operates the platform.
The company classified one leaked item as personal information: internal identification information, which it described as a unique internal numerical value generated for user identification at registration.
The remaining items, which Weverse Company said are not classified as personal information, were purchase type (payment method), payment gateway name, currency type, purchase amount, cancellation amount, purchase date and time, purchase status, and refund date and time for canceled purchases.
Names, contact details, and card numbers do not appear among the items Weverse Company listed.
The company said the Korea Internet & Security Agency (KISA) contacted it on September 3 (KST) to say an external reporter had flagged a security vulnerability in the Weverse service.
Weverse Company said it then ran an internal inspection and emergency response, and filed a breach incident report with KISA on September 4.
“Weverse Company recently received an external report regarding a security vulnerability in our service and immediately conducted an inspection,” said Yang. “As a result, we confirmed that the personal information of some customers had been leaked.
“We deeply apologize to all the fans who trust and support Weverse for causing great concern and worry through this incident.”
“WE INTEND TO PURSUE LEGAL RESPONSIBILITY REGARDING THE DAMAGE CAUSED BY THIS INCIDENT.”
ZOOIL YANG, WEVERSE
Weverse Company said it has since tightened access controls on the API that processes payment information and removed internal identifier information from it to prevent external exposure.
The company said it has also carried out a separate procedure to notify affected customers of the leak, in line with criteria set out in relevant laws and regulations.
“The leaked internal identification information is not information that directly identifies an individual, such as a name or contact details; it is an identifier value used only within Weverse Company’s internal systems and cannot be used externally,” the company said. “It is unlikely that payment forgery or unauthorized fund transfers could occur based on these data items alone.”
Weverse Company added that it will investigate all of its externally exposed APIs to strengthen access control and minimize the information they expose, tighten control over its deployment processes, and heighten the sensitivity of its security monitoring.
“In addition, we have requested the retrieval of the relevant personal information from the external actor who illegally accessed it through an abnormal attack,” said Yang. “We intend to pursue legal responsibility regarding the damage caused by this incident.
“The Company takes full responsibility for this matter and will take all appropriate measures to address our customers’ concerns and worries. Once again, we sincerely apologize for the inconvenience caused to our customers.”
The Weverse Company notice does not identify the cause of the vulnerability, how long data was exposed, or how much of it has been recovered.
Nor does it say whether the external reporter who flagged the vulnerability and the external actor it says illegally accessed the data are the same party, or whether the affected accounts include users outside South Korea.
Weverse reached a record 14.43 million monthly active users in Q2 2026, according to HYBE’s most recent earnings release.
Total payment volume on the platform rose 12% quarter-over-quarter in Q2, while average revenue per paying user climbed 24% over the same period.
Weverse also passed 200 artist communities in the quarter, after adding P-pop acts BINI and SB19.
Parent company HYBE posted record quarterly revenue of KRW 1.45 trillion (approximately USD $967 million) in the same period, driven by the BTS WORLD TOUR ‘ARIRANG’.
Yang took over as President of Weverse Company on June 1, succeeding Joon Choi.
Universal Music Group invested in Weverse in 2024 as part of a 10-year deal that also gave UMG exclusive distribution rights to HYBE‘s music.
The leak is the second data incident Weverse Company has confirmed this year.
In a statement on January 5, the company said an internal employee had unlawfully leaked another person’s personal information and attempted to use it for private purposes.
Weverse Company said at the time that it had removed the employee from their duties, referred them to its disciplinary committee, and filed a criminal complaint.
Weverse‘s disclosure follows a larger breach at Tving, the South Korean video streaming service operated by CJ ENM.
That breach was reported on June 1, after an attacker used a stolen developer access key to reach Tving‘s internal systems.
A three-month government-civilian investigation announced by the Ministry of Science and ICT on September 3 found that data from 39.54 million Tving accounts had been compromised, along with 361 technical assets, including source code.
The ministry said that figure counts multiple accounts held by the same users, along with dormant and closed accounts, and that 22.06 million were active.
The data exposed at Tving spanned 20 categories comprising 70 types of information, including names, dates of birth, mobile phone numbers, email addresses, and connecting information, the ministry said. The type and extent of the data varied depending on how users had registered.
South Korea’s Personal Information Protection Commission has yet to determine the final scope of that breach or any penalties.
The ministry’s findings landed on the same day KISA contacted Weverse Company.Music Business Worldwide




