South Korean fashion platform 29CM, a Musinsa affiliate, said abnormal external access to an order-inquiry API on the 27th exposed approximately 160,000 customer records. The company said 138,841 cases involved names בלבד, while 21,011 included names along with email addresses, mobile phone numbers and shipping information. Payment details and account credentials, including usernames and passwords, were not compromised. 29CM blocked the access route, voluntarily reported the incident to the Korea Internet & Security Agency (KISA), and individually notified affected customers. It also created a website tool allowing authenticated customers to check the exposed data elements for 30 days. The company warned that the information could be used in smishing or voice-phishing attempts involving fake payment, refund or delivery problems, and advised customers to change reused passwords and correct personal information in delivery notes.