Personal data belonging to roughly 150,000 users of 29CM, an online fashion platform operated by Musinsa, was exposed after what appears to have been an unauthorized external intrusion.
29CM said Saturday on its official website that unauthorized external access to an API function used to look up order information had occurred Wednesday, exposing some customers' personal data. The company said it immediately blocked the access route upon detecting the problem and voluntarily reported the breach to the Korea Internet & Security Agency (KISA).
According to the company, 138,841 cases involved only a name being exposed, while 21,011 cases involved names, email addresses, mobile phone numbers and delivery information. The company said payment details and login credentials, including usernames and passwords, were not among the leaked data.
29CM sent individual notices to affected users detailing what information was compromised and what steps they should take. "We are taking this matter very seriously," the company said, adding that it would continue monitoring for secondary harm while conducting a ground-up review of its overall data security infrastructure to prevent a recurrence.
The company also urged users to be wary of text messages, phone calls or emails referencing their order history and claiming to flag payment, refund or delivery errors. It stressed that it would never ask users to enter passwords or verification codes via text or email, and advised anyone who had included personal information in delivery notes to update that information immediately.
why37@heraldcorp.com