Cyber & AI intelligence
Wasteland.
Briefs indexed2905
Issues30
Published Mondays07:30 CT
▣ Breach MUSINSA-DATA-BREAC 2026-09-28

Musinsa: 29CM Order API Breach Grows to About 230,000 Records

"The breach at Musinsa's 29CM fashion platform is larger than first disclosed. According to breach reports Musinsa filed with Korea's Personal Information Protection Commission (PIPC), the company told regulators about…"

The breach at Musinsa's 29CM fashion platform is larger than first disclosed. According to breach reports Musinsa filed with Korea's Personal Information Protection Commission (PIPC), the company told regulators about roughly 72,000 more records on top of the 159,852 it announced in late August. The records were obtained by the office of Rep. Kim Hyung-yeon and reported by Seoul Economic Daily. That puts the total at about 230,000 records. The new data includes customer order details, product reviews and records on staff at partner companies that sell on the platform. No threat actor has been named. The only access vector the company has disclosed is abnormal external access to an order-lookup API.

What Happened

The original count varies by outlet. Seoul Economic Daily, Aju Press, CHOSUNBIZ and the LinkedIn post give 159,852 records ("about 160,000"). Korea JoongAng Daily says about 159,000. The Herald Business and KPI News say "roughly 150,000". All of them cite the same breakdown, so the differences come from rounding.

The expansion rests mainly on one outlet. Only Seoul Economic Daily details the newly reported data. The article's headline says 70,000 records, but its URL slug says "30,000 more partner records", which may reflect an earlier draft. Alpha Biz separately confirms that partner-company contact data was "later found to have been exposed". Musinsa has not published a public statement confirming the new total.

What Was Taken

Initial disclosure: 159,852 records - 138,841 records exposed names only. - 21,011 records exposed names, email addresses, mobile phone numbers and delivery information.

Additional records (per Seoul Economic Daily's reading of the PIPC filings) - 32,262 member order records. 32,159 of them include name, email, phone, address, delivery memo, waybill, order number, order and product details, and exchange or return information. The other 103 contain only names and order information. - 3,999 review records. These include order numbers, masked email addresses, writer names, review image URLs and the dates reviews were posted or edited. - 35,955 records on executives and employees at partner companies. - Warehouse and store staff data: 2 names and 9 mobile phone numbers.

Those items add up to roughly 72,200 records. The company says payment data, account IDs and passwords were not exposed.

Why It Matters

The Attack Technique

The disclosed entry point is a customer-facing API used to look up order information. The root cause has not been made public. The LinkedIn post (from a security vendor) correctly warns against assuming a specific flaw such as broken object-level authorization (IDOR) or missing authentication. What is known is narrower: an order-lookup path returned personal data to an unauthorized external caller until it was shut down.

The later finds point to the same API reaching more than it should have. These include review data, partner-staff records and warehouse contacts, which suggests the endpoint could access far more data than one customer's own orders. No group has claimed the attack, and no leak-site listing has been reported.

What Organizations Should Do

  1. Check ownership on every order endpoint. On every order, review and lookup endpoint, confirm the caller owns the object being requested. A valid session alone is not enough.
  2. Rate-limit and alert. Limit lookup APIs and alert on unusual volume or enumeration patterns, such as sequential order numbers.
  3. Return only what is needed. Keep API responses minimal. Mask or leave out fields like delivery memos, waybills and partner contact data unless the caller strictly needs them.
  4. Scope the full blast radius before disclosing. Map every data store an exposed API can reach, not only the obvious table, so the first disclosure is complete.
  5. Warn partners and customers early. Brief merchants and customers on phishing that references real orders, and state clearly that you will never ask for passwords or verification codes by text or email.
  6. Treat certifications as a minimum. Keep testing APIs between audits rather than relying on ISMS or similar certifications to hold.

Sources: Musinsa Data Breach Widens With 70,000 More Records From Partners a... | 29CM data breach exposes 160,000 records; Korea probes as users war... | Musinsa's 29CM hit by suspected hack, exposing personal data of 150... | Musinsa Data Breach Exposes 160,000 Records Just Two Months After I... | 29CM Customer Data Breach Affects Nearly 160,000 Accounts Aju Press | 29CM data breach exposes personal information of 159,000 customers | 무신사, 몸집 키우기만 몰두하다 '보안 뒷전'…15만건 개인정보 유출 | Order lookup API. 159,852 customer records.