Weverse leaked what fans spend, not who they are
HYBE's superfan platform Weverse said on Sunday last week that data tied to 422,584 accounts had been exposed, including payment method, purchase amounts, cancellations and the times refunds were issued.
The notice, published on 6 September in the name of Weverse Company chief executive Yang Ju-il, said the Korea Internet and Security Agency had contacted the company on 3 September after an outside researcher reported a flaw in the service. Weverse filed a breach report with the agency the following day.
Five days after that notice, on Friday 11 September, Korea's amended Personal Information Protection Act took effect, lifting the ceiling on punitive fines from 3 per cent of the revenue related to a breach to 10 per cent of a company's total revenue where a large-scale leak is repeated or caused by intent or gross negligence.
The platform disclosed a 422,584-account exposure on 6 September. Five days later, Korea's ceiling on privacy fines went from 3 per cent of related revenue to 10 per cent of the lot.
Weverse classified a single item as personal information: an internal identifier generated when a user registers. It listed the rest as non-personal: payment type, the payment gateway used, currency, purchase amount, cancellation amount, purchase status, and the dates and times of purchases and refunds.
Weverse said the internal identifier cannot identify anyone directly, is used only inside its own systems and cannot be used from outside them, and that the exposed items on their own would make payment forgery or unauthorised transfers difficult.
Read as a set, though, the second list describes spending behaviour attached to a consistent account: method, amount, frequency, what was cancelled and when the money went back.
That behaviour is the asset the superfan business is built on. HYBE reported a record 14.43 million monthly active users on Weverse in its second-quarter results, and has said 178 artists are active on the platform, around nine in ten of them signed to companies other than HYBE.
Those companies have now watched their own fans' transaction records sit behind an interface on somebody else's platform. Every Western label building a superfan tier is buying a version of the same exposure.
The regulator that decides what happens next has become considerably more expensive. The Personal Information Protection Commission imposed ₩61.1bn in fines in 2024 and ₩167.8bn in 2025, then ₩680.4bn in the first half of 2026 alone (about £368m) according to Hankyung's analysis of its published decisions.
The commission has announced no investigation into Weverse. Nor has anyone said whether users outside Korea were among the 422,584 accounts, which matters in London, because Weverse serves British and European fans and the platform is the model Western labels are copying.
Weverse said it had tightened access controls on the payment-processing interface, stripped the internal identifier out of it, and would audit every externally exposed interface it operates.
The company learned of the flaw on 3 September and published its notice three days later. The duty to tell users at the point a company becomes aware that a leak is merely possible took effect on 11 September.
SOURCES (1) (2) (3) (4) (5) (6)RELATED ARTICLESLATESTMORE IN:

At least six labels from or led by designers based in Asia show at London Fashion Week this week, across four of the season's five days.