Image credit: Weverse via Music Business Worldwide. Source
HYBE’s fan platform Weverse has confirmed a data incident affecting 422,584 accounts, counted by account ID, after South Korea’s internet agency KISA contacted the company on September 3, 2026 about a reported security vulnerability.
In a notice from Weverse Company president Zooil Yang, the firm said an inspection found leaked internal identification numbers plus purchase-related fields such as payment method type, payment gateway name, currency, amounts, timestamps, purchase status, and refund timing when applicable. Names, contact details, passwords, and card numbers were not listed among the exposed items.
Weverse said it filed a breach report with KISA on September 4, notified affected users under local rules, tightened access controls on its payment-information API, and removed internal identifiers from externally exposed responses. Yang apologized to fans and said the company intends to pursue legal responsibility against the actor who accessed the data.
HYBE’s latest earnings put Weverse at a record 14.43 million monthly active users in Q2 2026 with more than 200 artist communities. Music Business Worldwide notes this is the second Weverse data incident disclosed this year, following a January case involving an employee.
