29CM personal information leak notice. /Courtesy of company website screenshot

On 29CM (Twenty-nine Centimeter), a fashion and lifestyle platform operated by Musinsa, 159,852 items of customer personal information were leaked externally.

Looking at the 29CM website on the 30th, the company said on the 29th that it confirmed an abnormal external access occurred on the API that links to view order information on the 27th, leading to a leak of some customers' personal information. The company explained that as soon as it identified the issue, it blocked the access route and voluntarily reported the leak to the Korea Internet & Security Agency (KISA).

The scale of the leak is 138,841 cases where only names were exposed, and 21,011 cases where names along with email addresses, mobile phone numbers, and delivery information were also taken. 29CM has completed individual notifications to affected customers and will operate, for 30 days, a page where users can verify the leaked items after identity verification.

29CM said, "Payment information and customer account information such as IDs and passwords were not included in the leaked items and are being safely protected," while adding, "As some personal information was leaked, please prepare for the possibility of secondary damage caused by its misuse."

It specifically asked users to be cautious about texts, calls, or emails that reference order history and provide guidance on payment, refund, or delivery errors. 29CM also noted that it does not ask for password or authentication code entry via text or email. It advised changing your password if you use the same one as on other sites and immediately editing any delivery requests that contain personal information.

In the notice, 29CM said it will thoroughly reexamine its security system and management framework and do its utmost to prevent a recurrence.

※ This article has been translated by AI. Share your feedback here.