Skip to content
Back to Blog
medium severity September 08, 2026 · 4 min read

Weverse Shop data leak of 422,584 accounts: what was exposed, what to do

If you received a notice from Weverse Shop, here’s what the filing says was exposed, and what to do about it.

Weverse Company confirmed that data from 422,584 Weverse Shop accounts leaked in early September 2026. Names, contact details, and payment-card numbers were not in the file, according to the company; an internal account number and purchase and refund records were. Weverse says it has already sent individual notices to the customers involved.

Weverse Shop data leak of 422,584 accounts: what was exposed, what to do

On 3 September 2026, Weverse Company was contacted by Korea's internet-security agency, KISA, about a reported security problem. After checking its systems, the company confirmed that data from 422,584 accounts had leaked. It filed a report with KISA on 4 September and posted a public customer notice on 6 September, signed by President Yang Zooil.

According to that notice, an internal identification number — a unique figure Weverse creates when someone registers — left the company, along with shop records: payment method, the name of the payment company that processed the charge, currency, purchase amount, cancellation amount, date and time of the purchase, whether the order went through, and refund date and time if it was cancelled. Weverse says those internal numbers do not contain names or contact details, and that it has already written to affected customers individually, as the law requires.

No names were taken. A full shopping record still was.

Every public account of this incident, including Weverse's own, leads with the same comfort: no names, no phone numbers, no emails, and an internal ID that “cannot be used outside its systems.” The company also says it is unlikely anyone could fake a payment or move money using only what leaked.

Those statements match the notice. They are also the wrong place to stop if you actually buy things on Weverse Shop.

What is now outside the company is a detailed sales list for 422,584 accounts. For each internal number, someone has when a purchase happened, how it was paid, which payment firm handled it, how much was spent, whether it was cancelled, and whether a refund went out — down to the time of day. That is not your name. It is still a picture of how a person shops, and for how much.

A message that says “your Weverse order of this exact amount on this exact date has a problem” is much easier to believe than a generic fake email, because the figures are real. The sender does not need your name from this leak if they can already reach you another way — a fan account, a comment, an address sitting in some other company's old records. The internal number is also a store customer number. Alone, it does not name you. If that same number is ever paired with a name or a login in a later leak or leftover file, this whole purchase history attaches to a real person. Weverse says it has now stopped exposing those numbers and tightened access to its systems. That does not bring back the copy that already left.

What to actually expect

  • If your account was one of the 422,584, Weverse says it has already sent you a personal notice. Trust that official shop message, not a direct message or a surprise email with a link.
  • You should not expect your name, home address, email, phone number, password, or payment-card number to have come from this incident. Weverse states those were not in the leaked file.
  • In the coming weeks you may see “refund,” “customs,” or “order problem” messages that quote a real amount and date. Anyone asking you to log in, send a picture of a card, or click a link to fix that order is not Weverse.
  • Weverse has asked the outside party to return the data and says it will pursue legal action. That is not the same as the copy being gone. Assume it is still out there.

What you can and cannot fix

The leaked file cannot be taken back. If your internal Weverse number and purchase history were among those 422,584 records, that copy is out. No company and no removal service can recall it. Weverse asking for the data back does not change that.

  • Treat exact-amount Weverse messages as the real problem. The near-term harm from this file is not someone opening accounts in your name. It is someone using a real purchase amount and date to talk you into handing over a login or a card. Stay inside the Weverse Shop or app you already use. Do not follow links from mail, texts, or social messages about this incident.
  • Use the company's own notice — not a search tool — as your only signal. Weverse says it wrote to affected customers one by one. There is no reliable public list of the 422,584 accounts. Any site that offers to “check if you were in the Weverse leak” is guessing or trying to collect your details. If an official notice has not arrived, that is all the company has told the public; nobody else can confirm your status.
  • You do not need to replace payment cards or freeze credit over this leak alone. Card numbers were not in the file Weverse described, and the company says unauthorised transfers from these fields are unlikely. Save that effort for a leak that actually has card numbers or government IDs.
  • Take down public purchase posts if you would not want them matched to a receipt. This leak did not publish your name. Order screenshots, unboxing photos that show prices and dates, and “just bought” updates are how a nameless line in a spreadsheet becomes recognisable as you. Those posts, unlike the leaked file, are something you can actually remove. People-search listings that add relatives, phone numbers, jobs, and old addresses are the usual next step after a names-and-addresses leak; this file, as Weverse described it, does not contain names or addresses, so that cleanup is not the lever here.

Report details & sourcing

Severity Medium includes account details that can be misused directly
Disclosed September 08, 2026
Last reviewed September 8, 2026
Affected Unconfirmed
Data exposed Internal account IDsPayment methodsPayment-gateway namesCurrency typesPurchase amountsCancellation amountsPurchase dates and timesPurchase statuses +1 more
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email