2026 29CM — order-lookup API breach; 138,841+ name records, 21,011 with contact/delivery data (KISA)
Data compromised
138,841 records with names; 21,011 records with names, emails, mobile numbers, and delivery details; payment info and account credentials not exposed per company
Technical writeup
Company-confirmed breach — August 27, 2026. 29CM (Musinsa affiliate e-commerce) said it detected abnormal external access to the API used to look up order details, blocked the access route, and voluntarily reported the incident to the Korea Internet & Security Agency (KISA). Seoul Economic Daily reported 138,841 records containing customer names and 21,011 records containing names, email addresses, mobile phone numbers, and delivery details; the company stated payment information and account credentials such as IDs and passwords were not among the exposed items. 29CM warned customers to watch for phishing referencing order histories, refunds, or delivery errors. recordsAffected 150000 reflects company language of more than 150,000 customers impacted; companyConfirmed true.
Root cause
Abnormal external access to order-detail lookup API; company blocked route and reported to KISA (Aug 27, 2026)