Weverse
Sep 2026 · Graded Attested · Media and Entertainment · Beyond the filings
WeverseSep 2026
Weverse leaked internal user IDs and purchase metadata for 422,584 accounts through an unnamed flaw in its payment information API, a flaw an external reporter found before Weverse did. The company's own inspection began only after KISA flagged it on September 3, confirming that the data already sat with an outside actor. Strengthening access controls after the leak is not a fix; it is an admission of what the API was never built to secure from the jump. No names, no contact details, only the payment trail attached to every one of those customers' accounts.
Weverse Notifies Users Of Data Leak
Initial attack type software vulnerability confirmed · Impact data theft confirmed
Not yet quantified
AAttestedMedia and EntertainmentAbout this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.