← 29CM

2026 29CM — order-lookup API breach; 138,841+ name records, 21,011 with contact/delivery data (KISA)

2026 150.0K records affected Share on X

Data compromised

138,841 records with names; 21,011 records with names, emails, mobile numbers, and delivery details; payment info and account credentials not exposed per company

Technical writeup

Company-confirmed breach — August 27, 2026. 29CM (Musinsa affiliate e-commerce) said it detected abnormal external access to the API used to look up order details, blocked the access route, and voluntarily reported the incident to the Korea Internet & Security Agency (KISA). Seoul Economic Daily reported 138,841 records containing customer names and 21,011 records containing names, email addresses, mobile phone numbers, and delivery details; the company stated payment information and account credentials such as IDs and passwords were not among the exposed items. 29CM warned customers to watch for phishing referencing order histories, refunds, or delivery errors. recordsAffected 150000 reflects company language of more than 150,000 customers impacted; companyConfirmed true.

Root cause

Abnormal external access to order-detail lookup API; company blocked route and reported to KISA (Aug 27, 2026)

References