Weverse has disclosed a data leak involving information tied to 422,584 account identifiers, exposing the less visible privacy risks created when music platforms combine fandom, commerce and detailed transaction histories.

The HYBE-owned fan platform said the exposed material included an internal user identifier along with purchase-related information such as payment method, payment gateway, currency, purchase and cancellation amounts, transaction timestamps, payment status and refund dates.

Weverse said names, telephone numbers, email addresses and payment-card numbers were not included in the information identified as leaked. That distinction is important: the incident should not be described as a confirmed theft of card numbers or direct contact information.

A timeline still being examined

According to the company’s notice, Korea’s Internet and Security Agency contacted Weverse on September 3 after receiving an external report. Weverse reported the incident to authorities on September 4 and notified affected users on September 6.

The company said it tightened access controls and removed the internal user identifier from the affected API. It has not publicly established that the exposed records were used for fraud, but transactional data can still reveal purchasing behavior, refund activity and the commercial relationship between fans and artists.

Why music companies should pay attention

Direct-to-fan platforms are valuable because they can connect artists with highly engaged audiences. They also create concentrated databases showing what fans bought, how they paid, how much they spent and whether they canceled or sought refunds.

Labels, managers and independent artists should ask their platform partners several basic questions:

  • Which fan and transaction fields are stored, and for how long?
  • Can internal identifiers be accessed through public or partner-facing APIs?
  • Which employees, contractors and outside vendors can reach the data?
  • How quickly must a platform notify artists and customers after discovering an incident?
  • Can creators export or delete information when they leave the service?

The incident also demonstrates why “no card numbers exposed” cannot be the end of a privacy assessment. Purchase history, time stamps and refunds can still be commercially sensitive, particularly when connected to a persistent account identifier.

Radio News Now will continue monitoring Weverse’s disclosures and any findings issued by Korean regulators. The number of affected accounts, the types of records identified and the remedial steps described here come from Weverse’s own notice; an independent regulatory determination has not yet been reported.

Source: Music Business Worldwide, September 8, 2026