Musinsa and 29CM: Musinsa subsidy 29CM's data breach affects 159,000 customers

Musinsa and 29CM: Musinsa subsidy 29CM's data breach affects 159,000 customers

29CM Data Breach Exposes Personal Information of 159,000 Customers

South Korean fashion and lifestyle platform 29CM, operated by Musinsa, disclosed a data breach on Sunday affecting approximately 159,000 customers. The incident stemmed from unauthorized external access to an API used for retrieving order information, which occurred on Thursday.

Of the impacted users, 138,841 had only their names exposed, while 21,011 faced a more severe leak, including names, email addresses, phone numbers, and delivery details. The company confirmed that payment information and account credentials (IDs/passwords) were not compromised.

Upon detecting the breach, 29CM blocked the access route, reported the incident to the Korea Internet & Security Agency (KISA), and notified affected customers about the exposed data. A dedicated webpage will be available for 30 days, allowing users to verify the extent of their data exposure.

While financial data remained secure, 29CM warned that the leaked information could be exploited for phishing scams, particularly via fraudulent messages, calls, or emails referencing orders, payments, or deliveries. The company advised users to change passwords if reused across platforms and to remove or update personal details in delivery instructions.

In a statement, 29CM apologized for the incident and pledged to review and strengthen its security systems to prevent future breaches.

Source: https://www.koreajoongangdaily.com/korea/musinsa-subsidy-29cms-data-breach-affects-159000-customers/12850723

MUSINSA 무신사 cybersecurity rating report: https://www.rankiteo.com/company/musinsacom

29CM cybersecurity rating report: https://www.rankiteo.com/company/29cm

"id": "MUS29C1788079914",
"linkid": "musinsacom, 29cm",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '159,000',
                        'industry': 'Fashion and Lifestyle',
                        'location': 'South Korea',
                        'name': '29CM',
                        'type': 'E-commerce platform'}],
 'attack_vector': 'Unauthorized external access to API',
 'customer_advisories': 'Affected customers notified, advised to change '
                        'passwords and update personal details. Warned about '
                        'phishing scams.',
 'data_breach': {'number_of_records_exposed': '159,000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Moderate to High',
                 'type_of_data_compromised': ['Names',
                                              'Email addresses',
                                              'Phone numbers',
                                              'Delivery details']},
 'date_detected': '2023-11-30',
 'date_publicly_disclosed': '2023-12-03',
 'description': 'South Korean fashion and lifestyle platform 29CM disclosed a '
                'data breach affecting approximately 159,000 customers due to '
                'unauthorized external access to an API used for retrieving '
                'order information. The breach exposed names, email addresses, '
                'phone numbers, and delivery details for some users, though '
                'payment information and account credentials were not '
                'compromised.',
 'impact': {'brand_reputation_impact': 'Yes',
            'data_compromised': 'Personal information (names, email addresses, '
                                'phone numbers, delivery details)',
            'identity_theft_risk': 'Yes',
            'payment_information_risk': 'No',
            'systems_affected': 'API for order information retrieval'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Need to strengthen security systems to prevent future '
                    'breaches, particularly API security.',
 'post_incident_analysis': {'corrective_actions': 'Review and strengthen '
                                                  'security systems',
                            'root_causes': 'Unauthorized external access to '
                                           'API'},
 'recommendations': 'Users should change passwords if reused, remove or update '
                    'personal details in delivery instructions, and be '
                    'cautious of phishing scams.',
 'references': [{'date_accessed': '2023-12-03', 'source': '29CM Disclosure'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to Korea '
                                                       'Internet & Security '
                                                       'Agency (KISA)'},
 'response': {'communication_strategy': 'Notified affected customers, '
                                        'dedicated webpage for 30 days',
              'containment_measures': 'Blocked the access route',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Review and strengthen security systems'},
 'title': '29CM Data Breach Exposes Personal Information of 159,000 Customers',
 'type': 'Data Breach',
 'vulnerability_exploited': 'API vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.