← Incident database

weverse-payment-api-2026 · Disclosed 2026-09-06

Weverse Company: unauthorized access and impact

Following an external vulnerability report, the company confirmed payment-API disclosure and strengthened access controls. 422,584 account IDs’ internal identifiers and transaction metadata were disclosed; names, contacts and card numbers were not reported leaked. The count is not stated to cover Japan alone.

Implementation

Outcome: Confirmed breach

Entry path and evidence

  • Assessment

    Following an external vulnerability report, the company confirmed payment-API disclosure and strengthened access controls.

    [s1]§§1-2
  • Reported fact

    422,584 account IDs’ internal identifiers and transaction metadata were disclosed; names, contacts and card numbers were not reported leaked. The count is not stated to cover Japan alone.

    [s1]§§1-2

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    API access controls were strengthened and internal identifiers removed; a complete public-API review and monitoring improvements are planned.

    [s1]§§1-2

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Strengthened API controls are reported, but the precise entry chain remains an assessment. Account identifiers and transaction metadata are not names or card credentials.

Sources

  1. [s1] Weverse Company · Primary source

    Weverse Company:事故に関する公表資料 ↗

    Reviewed 2026-10-09