Weverse account hacked? Here’s what to do
Move fast and in the right order: reclaim the account through Weverse’s official flow, kick the attacker out of every session, then close the door they came through — usually a password that leaked in a breach and was reused.
September 2026: payment records from 422,584 Weverse accounts were taken
Weverse Company, the HYBE subsidiary behind the fan platform, said on 6 September 2026 that someone had pulled payment records for 422,584 accounts through a weak spot in its payment API. The file holds an internal account number next to each purchase: how it was paid, which payment gateway handled it, the currency, the amount, the purchase date and status, and any cancellation or refund. Names, email addresses, phone numbers and card numbers are not among the items the company listed, and it says the data alone is unlikely to allow forged payments or transfers. The account password was not part of it either, so the thing to prepare for is a message that quotes one of your real purchases back to you.
Weverse Company’s notice of 6 September 2026, as reported by Korea JoongAng Daily (7 September), Music Business Worldwide and Digital Music News (8 September) and Music Ally (9 September 2026)
If your Weverse account was hacked: start recovery at the official page (help.weverse.io/weverse/article?faq-id=000006458), change the password to a unique one, sign out all other sessions, and re-check the recovery email and phone on the account. Then find out how the attacker got in — check whether your password appears in known breach data — and turn on two-factor authentication so it can’t happen again.
Recover your Weverse account, step by step
These steps follow Weverse’s official process. Official links only: account recovery · password reset.
Open the app’s account security settings (More, then Member Info, then Account Security) and go to the device list. Sign out any phone or browser you do not recognise, or use the option at the bottom of the list to sign out of every device at once.
Turn on the alert for logins from a new device or browser, and consider the overseas login block, which stops sign-ins from outside the country or region set on your account until you confirm them from your email.
If you sign in with an email and password, reset the password from the email sign-in screen, which sends a verification code to your address. If you signed up with a social account, secure that account instead and switch on its two-factor authentication.
Check your purchase and membership history in the app for anything you did not make, and dispute an unfamiliar charge with your card issuer as unauthorised.
For the next few months treat any message about a Weverse refund, cancellation, membership renewal or ticket presale as unverified, however accurate it sounds, and reach Weverse only through the app or help.weverse.io.
What trips people up with Weverse
- Weverse did not ask anyone to change a password, and the breach does not give one a reason to. Change it anyway if you reused it somewhere else, but do it because reuse is the real risk, not because this file contained credentials.
- Weverse lets people sign up with a social media account instead of an email and password, and says so in its own help centre. If that is how you sign in, the account worth locking down is the one at that provider, because it opens Weverse and whatever else is linked to it.
- The help centre lists no two-factor option for a Weverse account. What it does offer is a device list with remote log-out, alerts when a new device signs in, and a block on logins from outside the country you set as home, and those three are the settings to switch on now.
- Expect refund, cancelled-membership and presale emails that quote a real amount and a real date. Accurate purchase details prove only that the sender has the file. Check the order or subscription in the app yourself instead of following a link, and never enter card details to receive a refund.
- The leaked records came through the payment API, not through your card issuer, and the company says the items alone are not enough for forged payments. There is no need to cancel a card over this, though a quick look at the statement for anything you did not buy costs nothing.
What happened at Weverse in September 2026
On 3 September 2026 the Korea Internet & Security Agency told Weverse Company that an outside reporter had found a security hole in the service. The company reported an incident to the agency the next day, and on Sunday 6 September its chief executive, Joo-il Yang, published an apology and a notice to users. The hole was in the API that serves payment information: it let someone read purchase records that should only have been visible inside the company. Weverse says it has since tightened access to that API, stripped the internal account identifier out of what it returns, asked the party who took the data to hand it back, and intends to pursue them legally.
The list of what was taken is narrow and specific. For each of the 422,584 accounts there is an internal numeric user ID and a purchase history: the payment method, the name of the payment gateway, the currency, the amount paid, any amount cancelled, the date and time of the purchase, its status, and the date and time of any refund. What is missing from that list matters just as much. The company did not name names, email addresses, phone numbers, postal addresses or card numbers among the exposed items, and account passwords were not mentioned at all. On its own, a numeric ID and a record of what someone spent on memberships or merchandise does not identify a person or open an account.
That is not the same as harmless. A purchase history is exactly the detail that makes a fake email believable, and fan platforms already attract more than their share of scams around memberships, ticket presales and limited merchandise. Anyone who manages to link the ID to an email address, from another leak or from a reply to a phishing message, gets a customer whose spending habits they already know. The notices went to the accounts involved, so if you use Weverse from the US and heard nothing, the most likely reading is that your account was not in the set. There is no public lookup, because the file has not been published anywhere.
Still logged in? Lock the account down now
If you can still get in, you're racing the attacker. In this order: change the password to a long, unique one; sign out all other sessions/devices (the setting exists in Weverse's security settings); confirm the recovery email and phone number are yours (attackers quietly add their own so they can "recover" the account later); remove unfamiliar linked apps or API access; and turn on two-factor authentication. Only then deal with anything the attacker posted, sent or bought.
Got a "new login" alert from Weverse?
Treat it as real but verify it the safe way: never tap the link in the message itself (fake login alerts are a top phishing template for Weverse). Open the app or type the address yourself, check the active-sessions list in security settings, and if you see a device or location you don't recognize, sign it out and change your password immediately. If the alert was genuine, that password is burned — assume it's circulating and change it everywhere else you reused it.
Locked out of Weverse — email or phone was changed
This is the worst-case scenario and the most common complaint: the attacker changed the account email, phone number or password so the normal reset flow emails them, not you. Do NOT keep triggering password resets — they go to the hacker. Go straight to Weverse's dedicated recovery flow (link above), which is built for exactly this case: it verifies you by your original signup details, previous passwords, linked devices or a government ID / selfie check, bypassing the stolen email. Watch for the security notice Weverse sent to your OLD email when the address was changed — it usually contains a "revert this change" link that works for a limited time and is the fastest way back in.
Why this happened — and how to make sure it can’t again
About a third of account takeovers are credential stuffing: a password you used on Weverse (or the email behind it) leaked in some other company’s breach, and attackers replayed it here automatically. The FBI’s IC3 logged over 5,100 account-takeover complaints with $262M in losses in 2025 alone (IC3). Even when Weverse itself was never breached, your reused password from another site opens it.
So after recovery, check what’s already out there: our free scanner shows which known breaches and dark-web dumps include your email — and whether passwords were exposed with it.
Check my exposure — free →After you recover: three doors to close
- Unique password + 2FA. A password manager plus app-based two-factor stops both stuffing and phishing replays.
- Reset everywhere you reused that password — email first (it’s the master key), then bank, then the rest.
- Shrink your public footprint. Attackers research targets on data-broker sites (your address, phone, relatives — enough to social-engineer support lines). Our free opt-out guide covers 190 of them, step by step.
Hacked Weverse account, answered
How did my Weverse account get hacked?
The most common cause isn't a hack of Weverse itself — it's credential stuffing: a password you used on Weverse leaked from some other site's breach, and attackers tried it here automatically. Roughly a third of account takeovers happen this way, with phishing (fake Weverse login pages and alerts) close behind. That's why the first fix is a unique password, not just a new one.
Can I get my Weverse account back?
Usually yes. Use the official recovery flow (https://help.weverse.io/weverse/article?faq-id=000006458) — it can verify you even when the attacker changed the email and password. Be patient and respond quickly to follow-ups so the case stays open.
Should I just make a new Weverse account instead?
Not until you've tried recovery. The old account keeps your history and contacts — and while the attacker controls it, it will be used to scam people who trust you. Recover it, or at minimum report it as compromised so Weverse can lock it, before you start over.
The hacker placed orders or drained gift cards on my Weverse account — now what?
Report the orders as unauthorized through Weverse's support, dispute any card charges with your bank, and check saved addresses and payment methods for ones the attacker added. Loyalty points and gift-card balances are a favorite target because people don't watch them like a bank account — screenshot balances and include them in the report.
Was Weverse hacked in 2026?
Weverse Company confirmed on 6 September 2026 that payment records for 422,584 accounts were read through a vulnerability in its payment API, which an outside reporter had flagged to Korea’s Internet & Security Agency three days earlier. The company called it a data leak rather than a break-in to user accounts, and no account passwords were named among the exposed items.
What data was leaked in the Weverse breach?
An internal numeric account ID plus purchase details: payment method, payment gateway, currency, amount paid, amount cancelled, purchase date and time, purchase status, and refund date and time. The company did not list names, contact details or card numbers.
Were my card details stolen from Weverse?
Card numbers are not among the items Weverse Company listed, and it says the data alone is unlikely to be enough for forged payments or unauthorised transfers. What was taken is the record of what you bought and how, which is useful for a convincing scam email rather than for charging your card directly.
Do I need to change my Weverse password?
Not because of this incident, since passwords were not part of the exposed data. Change it if the same password protects any other account. If you signed up to Weverse with a social media account, the password that matters is the one on that account.
How do I know if my Weverse account was affected?
Weverse says it notified the affected customers as the law requires, so check the email address on your account and your in-app notices. Nothing from this incident has been published as a searchable file, so no outside checker can tell you, and a site offering to do so is more likely to be collecting details than protecting them.
How do I stop my Weverse account being hacked again?
Three things close most of the doors: a unique password (a manager makes this painless), app-based two-factor authentication, and shrinking your exposed footprint — checking your email against known breach databases and removing your personal data from data-broker sites that attackers use to research targets.