Sunday, August 30, 2026

29CM leaks 159,000 pieces of personal data, exposing names, phone numbers and delivery information

Input
2026-08-30 10:42:38
Updated
2026-08-30 10:42:38
29CM posted a notice about the personal data breach on its website. / Photo captured from the 29CM website

[Financial News] About 159,000 pieces of customer personal data were leaked from 29CM, the fashion and lifestyle platform operated by MUSINSA, after unauthorized external access. In some cases, not only names but also email addresses, mobile phone numbers and delivery information were exposed.

According to 29CM on the 29th, it confirmed on the 27th that unauthorized external access had occurred through an API linked to its order information inquiry service.

The investigation found that a total of about 159,000 personal data records were leaked, and all of them included customer names. Of those, 21,011 records were found to include names along with email addresses, mobile phone numbers and delivery information.

The company said payment information, as well as account details such as IDs and passwords, were not leaked.
29CM blocked the problematic access route immediately after discovering the incident. It then voluntarily reported the breach to the Korea Internet & Security Agency (KISA) and the Personal Information Protection Commission (PIPC), and is carrying out additional protective measures with the relevant authorities.
The company also separately informed affected customers of the leaked items and how to respond to prevent secondary damage. For 30 days from the date of the notice, customers can verify whether their personal data was leaked and check the specific items after completing identity verification.
29CM also warned customers about the possibility of secondary damage, including smishing and phishing using the leaked information.
In particular, it asked customers to verify the sender and avoid clicking suspicious links if they receive text messages, phone calls or emails mentioning actual order details and referring to payment, refunds or delivery errors.
It also advised customers who entered separate personal information, such as a shared building entrance password, in delivery requests to change that information and to update their passwords if they use the same one on other online services.


[email protected] Seo Yoon-kyung Reporter