A data breach at 29CM, a fashion and lifestyle platform operated by Musinsa, has compromised the personal information of 159,852 customers. Among the leaked data, over 20,000 records included names, email addresses, mobile phone numbers, and shipping information.
According to 29CM, abnormal external access to its order information API was detected on August 27, leading to the exposure of some customer data.
The leaked information includes 138,841 records containing names and 21,011 records that include names, email addresses, mobile phone numbers, and shipping details, totaling 159,852 records.
However, the company clarified that payment information, account IDs, and passwords were not part of the breach.
Upon confirming the unauthorized access, 29CM immediately blocked the access route and voluntarily reported the data breach to the Korea Internet & Security Agency (KISA).
Customers whose information was compromised have been informed about the specific data exposed and measures to prevent secondary damage. A related notice was posted on the 29CM website on August 29.
Customers can verify whether their personal information has been leaked by undergoing identity verification on the website. This verification service will be available for 30 days from the date of the notice.
29CM advised customers to be cautious of messages, calls, or emails regarding order details, payments, refunds, or shipping errors. The company also noted that it does not request passwords or authentication codes via text or email.
Additionally, customers are encouraged to change or delete any passwords that are the same as those used on other sites or that contain personal information in shipping requests.
A 29CM representative stated, "We take this matter very seriously and will thoroughly review our security systems and management processes to better protect customer information and prevent future incidents."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.