惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
H
Hackread – Cybersecurity News, Data Breaches, AI and More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
小众软件
小众软件
月光博客
月光博客
D
DataBreaches.Net
L
LangChain Blog
美团技术团队
S
SegmentFault 最新的问题
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Help Net Security
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog
I
InfoQ
U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
腾讯CDC
Martin Fowler
Martin Fowler

Consumer Insights

Manchester Airports Group cyberattack exposes data of 8.7 million customers Sakura Internet hack may affect 1.36 million accounts French tax authority breach exposes data of 678,000 people and businesses Phone number leaked in the Bloctel breach? Here’s what to do. SplitVPN breach reveals 58 million hidden connection logs South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025
Weverse data breach affects 422,584 user accounts
Alina BÎZGĂ · 2026-09-07 · via Consumer Insights

Weverse, the global fan platform used by millions of K-pop fans, has disclosed a data breach affecting 422,584 user accounts.

The exposed information includes internal account identifiers and details about purchases, payments and refunds. Affected users should be wary of messages that might be using the breach as a pretext to steal passwords, payment information or money.

Key takeaways

  • The breach affected 422,584 Weverse accounts
  • Exposed data included internal user identifiers and transaction information
  • Names, contact details, passwords and card numbers were not listed among the compromised data
  • Fans should watch for fake security alerts, refund messages and payment-related phishing attempts

What happened?

According to Weverse, the company was contacted by the Korea Internet & Security Agency (KISA) on Sept. 3 after an external party reported a vulnerability in the service.

An internal investigation confirmed that an external actor had accessed user information in what the company described as an abnormal attack.

Weverse reported the incident to KISA on Sept. 4 and started notifying affected users. The company also strengthened access controls for the application programming interface, or API, used to process payment information and removed internal identifiers from externally exposed data.

Weverse says it plans to inspect all externally accessible APIs, tighten its deployment processes and improve security monitoring. It has also said it intends to pursue legal action against the person responsible for accessing the data.

What information was exposed?

The breach affected 422,584 records at the account ID level. The exposed information included:

  • An internal numerical identifier generated when a user creates an account
  • Purchase or payment method type
  • Payment gateway provider
  • Currency used
  • Purchase amount
  • Cancellation amount
  • Purchase date and time
  • Purchase status
  • Refund date and time, when applicable

Weverse said the internal identifiers are used only within its systems and can’t directly identify individuals in the way a name, email address or phone number can.

The company did not list passwords, names, contact details or complete payment card information among the exposed data. It also said that payment forgery or unauthorized transfers would not likely be using the compromised information alone.

Why Weverse users should still be careful

Even when a breach doesn’t expose passwords or card numbers, scammers can take advantage of the confusion and publicity surrounding the incident.

Fans may receive emails, texts or direct messages claiming that:

  • Their Weverse account has been suspended
  • A recent purchase must be verified
  • A membership payment failed
  • They are entitled to a refund
  • Their password must be reset immediately
  • An order or concert-related purchase has been canceled

These messages may lead to fake Weverse login pages designed to steal account credentials and payment information. Criminals don’t necessarily need access to the leaked database to send this type of phishing message.

If transaction information from the incident were ever matched with information exposed elsewhere, it could also help make a scam appear more believable. At this time, there is no public indication that this has happened.

As we explained in our guide to K-pop scams and how fans can stay safe, criminals already impersonate fan platforms, entertainment companies, ticket sellers and official fan clubs. A widely reported breach gives them another convincing story to use.

What should Weverse users do?

  • Check whether you received an official breach notification from Weverse
  • Open the Weverse app or type the official website address yourself instead of following links in emails, texts or direct messages
  • Review your order history and payment statements for anything you do not recognize
  • Be suspicious of unexpected refund, cancellation or account-verification messages
  • Never provide passwords, verification codes or payment details in response to an unsolicited message
  • Use a unique password for Weverse—if you reuse the same password elsewhere, replace it with a strong, unique one on every affected account
  • Enable additional sign-in security wherever it is available
  • Contact Weverse or your payment provider through its official website if you notice suspicious activity

Keep track of your exposed information

One breach may reveal only a small part of your digital identity. However, information from separate leaks can be combined to create more complete profiles for phishing, impersonation and account takeover attempts.

Bitdefender Digital Identity Protection monitors your personal information across public sources and the dark web, alerts you when it appears in a data breach and provides clear steps for securing affected accounts.

Knowing what information has been exposed gives you the chance to act before scammers have an opportunity to use it against you.