29CM says API breach exposed about 160,000 customer records

  • 29CM said abnormal order-inquiry API access exposed approximately 160,000 customer records.
  • 21,011 records included names, contact details and shipping information; 138,841 contained names only.
  • 29CM blocked access, notified affected customers and reported the incident to KISA.

South Korean fashion platform 29CM, a Musinsa affiliate, said abnormal external access to an order-inquiry API on the 27th exposed approximately 160,000 customer records. The company said 138,841 cases involved names בלבד, while 21,011 included names along with email addresses, mobile phone numbers and shipping information. Payment details and account credentials, including usernames and passwords, were not compromised. 29CM blocked the access route, voluntarily reported the incident to the Korea Internet & Security Agency (KISA), and individually notified affected customers. It also created a website tool allowing authenticated customers to check the exposed data elements for 30 days. The company warned that the information could be used in smishing or voice-phishing attempts involving fake payment, refund or delivery problems, and advised customers to change reused passwords and correct personal information in delivery notes.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.