Weverse
Everything you play is logged and turned into a guess at your tastes, and that profile is traded both ways: your interests go out to advertisers, demographic data is bought back in. Almost no policy says how long it is kept.
Reported incidents
Purchase and refund records of 422,584 fan accounts exposed through its APIs
2026-09-08Affected Weverse Shop payment records and external APIs
Weverse, the HYBE-owned fan platform, told users in September 2026 that data tied to 422,584 accounts had been taken. Korea's Internet and Security Agency told the company of a vulnerability on 3 September after an outside party reported it, and Weverse filed a breach report on 4 September. The exposed data was an internal account number plus purchase records: payment method, payment gateway, currency, amounts, purchase and refund dates and times. Weverse did not list passwords, names, contact details or full card numbers. It said it has tightened access controls and will review all of its externally exposed APIs.
People affected typically ask Weverse to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.