HYBE’s fan platform Weverse has confirmed a major security breach that affected more than 422,000 user accounts. The company announced the data leak on September 6, 2026, through an official notice signed by CEO Yang Joo-il. The incident has raised concerns among K-Pop fans worldwide who use the platform to connect with artists like BTS, LE SSERAFIM, and others.
The breach came to light after the Korea Internet & Security Agency (KISA) notified Weverse on September 3 about a security vulnerability reported by an external source. The company immediately launched an internal investigation and found that 422,584 user accounts had been affected.
What Data Was Actually Leaked
According to the official announcement, the leaked information includes internal identification numbers that the system generates when users register. These are numerical values used only within Weverse’s internal systems to identify users.
CEO Yang Joo-il clarified that the leaked data does not include names, phone numbers, or any direct contact information that could personally identify users. He stated that the internal identification codes cannot be used outside the company’s system, making it difficult for hackers to commit payment fraud or illegal transfers using only this information.
“The leaked internal identification information is not information that directly identifies individuals, such as names or contact information, but rather an identification value used only within the Weverse Company internal system and cannot be used externally.” – Yang Joo-il, Weverse Company CEO
Besides internal IDs, the breach also exposed transaction-related details including payment methods, payment gateway names, currency types, purchase amounts, cancellation amounts, purchase dates and times, order statuses, and refund dates. The company clarified that these are considered general information items and do not fall under personal information under relevant laws.
How Weverse Is Responding to the Security Breach
Weverse Company has taken immediate steps to strengthen security following the discovery of the leak. The company tightened access controls on the payment information processing API and removed internal identifiers to prevent further exposure.
The company submitted a report to KISA on September 4 detailing the inspection results and response measures. Weverse has also started notifying affected customers individually according to legal requirements.
CEO Yang announced that the company will conduct a comprehensive investigation of all external exposure APIs to strengthen access control and minimize exposed information. Security monitoring will also be increased to prevent similar incidents from happening again.
“We will conduct a comprehensive investigation of external exposure APIs to strengthen access control and minimize exposed information, and we will heighten the sensitivity of security monitoring in the deployment process to do our utmost to prevent similar incidents from recurring.” – Yang Joo-il, Weverse Company CEO
Legal Action Against the Hackers
Weverse Company has requested the recovery of personal information from the external actor who illegally accessed the data through an abnormal attack. The company plans to hold those responsible legally accountable for the damage caused.
CEO Yang stated that criminal charges will be filed against the perpetrators. The company has also requested the unauthorized party to delete or return the related data.
Fan Reactions and Concerns
The news has sparked worry among K-Pop fans who use Weverse to follow their favorite artists. Many users took to social media to express concerns about their data security, even though the company assured that sensitive personal information was not compromised.
Some fans questioned why it took time for the breach to be discovered and reported. Others appreciated the transparency but demanded more details about how the vulnerability occurred and what measures are being taken to ensure it does not happen again.
Weverse has not yet disclosed the specific cause of the breach, the full extent of the unauthorized access, or how much of the affected data has been recovered. This lack of detail has left some users feeling uneasy.
You May Also Like:
What This Means for Weverse Users
For the millions of K-Pop fans who use Weverse daily, this incident serves as a reminder about online data security. The platform is home to communities for major K-Pop acts including BTS, LE SSERAFIM, and other HYBE artists, as well as Japanese artists like YOASOBI.
Weverse Company has apologized sincerely to its users. The official notice expressed deep regret for the concern and inconvenience caused to fans who have trusted and valued the platform.
“We are fully responsible for this issue and will take all appropriate measures to address our customers’ concerns. Once again, we sincerely apologize for the inconvenience caused.” – Yang Joo-il, Weverse Company CEO
The company has committed to doing everything possible to restore user trust and prevent future security incidents.
Also Read: The Early Spring on Netflix: Why This Chinese Drama Keeps Dominating India’s Top 5
Stay updated with more entertainment news and updates on VvipTimes.
Source: (1)







































































































Leave a Reply