Weverse, the fan platform operated by HYBE-affiliated Weverse Company, has confirmed a security incident that affected 422,584 user accounts. The company said the exposed information consisted mainly of internal identifiers that cannot be used outside the platform.
On September 6, Weverse Company, which operates Weverse under South Korean entertainment giant HYBE, announced that 422,584 accounts had been affected by a security vulnerability.

“We received a notification from the Korea Internet & Security Agency (KISA) on September 3 that an external source had reported a security vulnerability in the Weverse service. We immediately launched an internal investigation and took emergency response measures,” Weverse Company President Yang Zooil said.
The investigation identified 422,584 affected accounts. According to Weverse, the exposed information included internal identifiers—unique strings automatically generated by the system when users create accounts to identify them within the platform.
The company emphasized that these identifiers were not users’ names, phone numbers, or other contact information that could directly reveal their identities. The identifiers are used exclusively within Weverse’s internal systems and cannot be utilized outside the platform.

Certain transaction-related information was also accessed. This included purchase or payment methods, the name of the payment gateway, transaction currency, payment amounts, canceled amounts, purchase times, transaction statuses, and refund times for canceled transactions.
Weverse said this information does not directly identify individual users and did not include payment details that could be used to facilitate unauthorized money transfers.
After discovering the incident, Weverse strengthened security measures surrounding the APIs used to process payment-related information. The company also tightened access controls and removed internal identifiers from data that could potentially be exposed externally.

On September 4, Weverse submitted an incident report to KISA and began separately notifying affected customers in accordance with legal requirements. The company also requested that the unauthorized party delete or return the relevant data and said it plans to pursue legal measures to hold those responsible accountable for any damages resulting from the incident.
“We take full responsibility for this matter and will take all appropriate measures to address our customers’ concerns. Once again, we sincerely apologize for the inconvenience caused,” Yang said.
Despite the announcement, Weverse has yet to disclose several details that users are likely to be concerned about, including the specific cause of the breach, the actual scope of unauthorized access, how much of the affected data has been recovered, and whether there is any possibility of further incidents.
While Weverse maintains that the leaked data cannot be used outside its system, the incident nevertheless highlights the growing security demands facing digital fandom platforms that handle information belonging to millions of fans around the world.
This is not the first time Weverse has faced controversy over the handling of user information in 2026. In early January, Weverse Company confirmed that an internal employee had improperly shared personal information belonging to participants in fan events.
The employee was found to have shared the names and birth years of fans participating in a fansign through a private group chat. The employee also reportedly photographed and distributed a list of 30 participants from another event containing their names, dates of birth, and phone numbers.

Weverse subsequently suspended the employee, referred the individual to a disciplinary committee, and filed a criminal complaint.
Launched in 2019, Weverse was initially introduced as a community application connecting artists with their fans. The platform has since evolved into a broader ecosystem combining fan communities, content, and commerce, allowing users to communicate with artists, access exclusive content, watch concerts online, and purchase merchandise.
According to Weverse Company, the platform is currently available in 245 countries and territories. It has recorded more than 150 million downloads, over 13 million monthly active users as of the first quarter of 2026, and more than 178 participating artists.
Weverse is home not only to artists under HYBE but also to acts from other Korean entertainment companies, including BLACKPINK and aespa, as well as international stars such as Ariana Grande and Dua Lipa. The company said Weverse Shop processes more than 25 million purchases each year.
According to The Straits Times, BTS’s Weverse community became the first on the platform to surpass 30 million followers.
Sources: Star News


