Skip to main content
market.news โ€” Markets without borders
Home/๐Ÿ‡ฐ๐Ÿ‡ท South Korea/Korean Fashion Platform 29CM Leaks 159,000 Customer Records in API Security Breach
๐Ÿ‡ฐ๐Ÿ‡ท South Korea

Korean Fashion Platform 29CM Leaks 159,000 Customer Records in API Security Breach

Fashion platform 29CM confirmed a data breach on August 27 that exposed approximately 159,852 customer records through unauthorized external access to an order-inquiry API.

Anjali Mehta
Asia Markets Desk
ยทPublished Aug 30, 2026, 1:57 PM UTCยท 1 min read๐Ÿค– AI-Synthesized

TLDR

  • โ—Fashion platform 29CM confirmed a data breach on August 27 that exposed approximately 159,852 customer records through unauthorized external access to an order-inquiry API.
  • โ—21,011 records included full contact and delivery address details; 138,841 records exposed names only.
  • โ—Parent company Musinsa blocked the breach immediately and self-reported to Korea Internet Safety Agency KISA.
Editorial Self-Reviewยท85/100Publish tier
Strengths
  • Specific breach numbers confirmed across 3 Korean sources
  • Regulatory and market implications clearly articulated
Considered limitations
  • All sources tier 2 Korean outlets; limited international corroboration
Our AI editor's self-review of this synthesis. We show our work โ€” including where coverage is limited or sources are thin โ€” so you can weight insights accordingly.

Why this matters

Coverage sentiment: Bearish (0 bullish ยท 1 neutral ยท 2 bearish)

Korea's PIPA-driven regulatory response to the breach sets a template for data protection enforcement across Asia, where similar personal data protection laws are being strengthened in India, Singapore, and Japan.

What to watch

  • โ€ข KISA enforcement action and timeline for penalty assessment under PIPA
  • โ€ข Musinsa IPO preparation timeline and whether breach affects valuation

Ripple effects

  • โ€ข Regulatory scrutiny of Korean e-commerce API security standards set to intensify

AI-Synthesized news from multiple sources

This article was synthesized by AI from the source articles listed below, reviewed by a second-pass AI quality reviewer, and published by the market.news editorial system. How we do this ยท Editorial standards ยท Report an error

The Quick Take

  • Fashion platform 29CM confirmed a data breach on August 27 that exposed approximately 159,852 customer records through unauthorized external access to an order-inquiry API.
  • 21,011 records included full contact and delivery address details; 138,841 records exposed names only.
  • Parent company Musinsa blocked the breach immediately and self-reported to Korea Internet Safety Agency KISA.
  • Payment information, account IDs, and passwords were confirmed not included in the leaked data.

The 29CM breach adds to a growing list of API-related security incidents at South Korean consumer platforms, exposing systemic vulnerabilities in how order inquiry systems are secured against unauthorized external access. Musinsa, which operates 29CM as part of its fashion e-commerce portfolio, faces immediate regulatory scrutiny under Korea's Personal Information Protection Act, which mandates breach notification and can impose fines proportional to affected records. With nearly 160,000 records exposed, the financial exposure to regulatory penalties and potential class action litigation is non-trivial for a company navigating an anticipated IPO timeline.

The market implications extend beyond 29CM itself. Musinsa is Korea's largest domestic fashion e-commerce operator, and any erosion of consumer trust could accelerate customer churn toward rivals including Kakao Style, Naver Shopping, and international players. The breach may also trigger mandatory security audits of other Musinsa-operated platforms, creating near-term compliance costs. E-commerce platforms with Korean listings and investors tracking Musinsa's IPO valuation will watch closely for signs that reputational damage is affecting user engagement metrics in coming weeks.

Forward signals to watch include the KISA investigation timeline and any formal penalty assessment under PIPA enforcement guidelines. Civil litigation from affected consumers could create multi-year liability risk and set precedents for damages in Korean data breach cases. Musinsa's responseโ€”including a 30-day customer notification portalโ€”reflects awareness of reputational stakes. Security technology vendors serving Korean e-commerce are likely to see increased procurement interest as platforms rush to audit their API security postures following this high-profile breach at a major operator.

Synthesized from 3 sources.

AI Indicators

Market Intelligence Panel

Sentiment

Bearish
๐ŸŸข 0โšช 1๐Ÿ”ด 2

Coverage

live
3

sources covering this story

T1: 0T2: 3T3: 0

Live Price

KRX:KOSPI

๐ŸŒ India / Asia Angle

Korea's PIPA-driven regulatory response to the breach sets a template for data protection enforcement across Asia, where similar personal data protection laws are being strengthened in India, Singapore, and Japan.

๐ŸŒŠ Ripple Effects

  • โ–ธRegulatory scrutiny of Korean e-commerce API security standards set to intensify
  • โ–ธMusinsa faces compliance costs and potential civil litigation from 159,000 affected customers
  • โ–ธData security vendor demand likely to rise among Korean consumer tech platforms

๐Ÿ”ญ What to Watch Next

PRO
  • โ–ธKISA enforcement action and timeline for penalty assessment under PIPA
  • โ–ธMusinsa IPO preparation timeline and whether breach affects valuation
  • โ–ธBroader sector impact if PIPA enforcement sets new precedents on fine levels

Market news synthesis. Not financial advice. Sources cited above.

Timeline

How the Story Spread

3 publishers ยท 2 time windows
Aug 30, 12:00 AM
+1 source ยท total: 1
All Sources

3 publishers covering this story

โ— Tier 2: 3

AI synthesis of every source listed below. Tier 1 = wire services (AP, Reuters via wire, Bloomberg, official central banks). Tier 2 = major financial publishers. Tier 3 = niche / specialist outlets. Click any card to read the original article.

โ— Tier 2 โ€” Major publishers

๋™์•„์ผ๋ณด (๊ฒฝ์ œ)TIER 2donga.com15h ago

29CM, ๊ณ ๊ฐ ์ •๋ณด 15๋งŒ9000๊ฑด ์œ ์ถœโ€ฆ๋ฐฐ์†ก์ •๋ณด ํฌํ•จ 2๋งŒ๊ฑด

๋ฌด์‹ ์‚ฌ๊ฐ€ ์šด์˜ํ•˜๋Š” ํŒจ์…˜ยท๋ผ์ดํ”„์Šคํƒ€์ผ ํ”Œ๋žซํผ 29CM์—์„œ 15๋งŒ9000์—ฌ๊ฑด์˜ ๊ณ ๊ฐ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ์œ ์ถœ๋๋‹ค. 30์ผ 29CM๋Š” ํ™ˆํŽ˜์ด์ง€ ๊ณต์ง€๋ฅผ ํ†ตํ•ด ์ง€๋‚œ 27์ผ ์ฃผ๋ฌธ์ •๋ณด๋ฅผ ์กฐํšŒํ•˜๋Š” ์—ฐ๋™ ๊ธฐ๋Šฅ(API)์— ์™ธ๋ถ€์˜ ๋น„์ •์ƒ์ ์ธ ์ ‘๊ทผ์ด ๋ฐœ์ƒํ•ด ์ผ๋ถ€ ๊ณ ๊ฐ์˜ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ์œ ์ถœ๋œ ์‚ฌ์‹ค์„ ํ™•์ธํ–ˆ๋‹ค๊ณ  ๋ฐํ˜”๋‹ค.์ด๋ฆ„๋งŒ ์œ ์ถœ๋œ ๊ฒฝ์šฐ๊ฐ€ 13๋งŒ8841๊ฑด, ์ด๋ฆ„๊ณผ ์ด๋ฉ”์ผ์ฃผ์†Œ, ํœด๋Œ€์ „ํ™”๋ฒˆํ˜ธ, ๋ฐฐ์†ก์ •๋ณด๊ฐ€ ํ•จ๊ป˜ ์œ ์ถœ๋œ ๊ฒฝ์šฐ๊ฐ€ 2๋งŒ1011๊ฑด์ด๋‹ค.29CM๋Š” ๋ฌธ์ œ๋ฅผ ํ™•์ธํ•œ

Read on ๋™์•„์ผ๋ณด (๊ฒฝ์ œ)
๋‰ด์‹œ์Šค (์‚ฐ์—…)TIER 2newsis.com15h ago

29CM, ๊ณ ๊ฐ ์ •๋ณด 15๋งŒ9000๊ฑด ์œ ์ถœโ€ฆ๋ฐฐ์†ก์ •๋ณด ํฌํ•จ 2๋งŒ๊ฑด

[์„œ์šธ=๋‰ด์‹œ์Šค]์ด์ฃผํ˜œ ๊ธฐ์ž = ๋ฌด์‹ ์‚ฌ๊ฐ€ ์šด์˜ํ•˜๋Š” ํŒจ์…˜ยท๋ผ์ดํ”„์Šคํƒ€์ผ ํ”Œ๋žซํผ 29CM์—์„œ 15๋งŒ9000์—ฌ๊ฑด์˜ ๊ณ ๊ฐ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ์œ ์ถœ๋๋‹ค. 30์ผ 29CM๋Š” ํ™ˆํŽ˜์ด์ง€ ๊ณต์ง€๋ฅผ ํ†ตํ•ด ์ง€๋‚œ 27์ผ ์ฃผ๋ฌธ์ •๋ณด๋ฅผ ์กฐํšŒํ•˜๋Š” ์—ฐ๋™ ๊ธฐ๋Šฅ(API)์— ์™ธ๋ถ€์˜ ๋น„์ •์ƒ์ ์ธ ์ ‘๊ทผ์ด ๋ฐœ์ƒํ•ด ์ผ๋ถ€ ๊ณ ๊ฐ์˜ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ์œ ์ถœ๋œ ์‚ฌ์‹ค์„ ํ™•์ธํ–ˆ๋‹ค๊ณ  ๋ฐํ˜”๋‹ค. ์ด๋ฆ„๋งŒ ์œ ์ถœ๋œ ๊ฒฝ์šฐ๊ฐ€ 13๋งŒ8841๊ฑด, ์ด๋ฆ„๊ณผ ์ด๋ฉ”์ผ์ฃผ์†Œ, ํœด๋Œ€์ „ํ™”๋ฒˆํ˜ธ, ๋ฐฐ์†ก์ •๋ณด๊ฐ€ ํ•จ๊ป˜ ์œ ์ถœ๋œ ๊ฒฝ์šฐ๊ฐ€ 2๋งŒ101

Read on ๋‰ด์‹œ์Šค (์‚ฐ์—…)
์กฐ์„ ์ผ๋ณด (๊ฒฝ์ œ)TIER 2chosun.com16h ago

29CM, ๊ฐœ์ธ์ •๋ณด ์œ ์ถœโ€ฆ ์ด๋ฆ„ 13๋งŒ๊ฑด, 2๋งŒ๊ฑด์€ ๋ฐฐ์†ก์ง€ ํฌํ•จ

๋ฌด์‹ ์‚ฌ๊ฐ€ ์šด์˜ํ•˜๋Š” ํŒจ์…˜ยท๋ผ์ดํ”„์Šคํƒ€์ผ ํ”Œ๋žซํผ 29CM(์ด์‹ญ๊ตฌ์„ผํ‹ฐ๋ฏธํ„ฐ)์—์„œ ๊ณ ๊ฐ ๊ฐœ์ธ์ •๋ณด 15๋งŒ9852๊ฑด์ด ์™ธ๋ถ€๋กœ ์œ ์ถœ๋๋‹ค. 30์ผ 29CM ํ™ˆํŽ˜์ด์ง€๋ฅผ ๋ณด๋ฉด, ํšŒ์‚ฌ๋Š” ์ง€๋‚œ 27์ผ ์ฃผ๋ฌธ์ •๋ณด๋ฅผ ์กฐํšŒํ•˜๋Š” ์—ฐ๋™ ๊ธฐ๋Šฅ(API)์— ์™ธ๋ถ€์˜ ๋น„์ •์ƒ์ ์ธ ์ ‘๊ทผ์ด ๋ฐœ์ƒํ•ด ์ผ๋ถ€ ๊ณ ๊ฐ์˜ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ์œ ์ถœ๋œ ์‚ฌ์‹ค์„ ํ™•์ธํ–ˆ๋‹ค๊ณ  29์ผ ๊ณต์ง€ํ–ˆ๋‹ค. ํšŒ์‚ฌ ์ธก์€ ๋ฌธ์ œ๋ฅผ ํ™•์ธํ•œ ์ฆ‰์‹œ ํ•ด๋‹น ์ ‘๊ทผ ๊ฒฝ

Read on ์กฐ์„ ์ผ๋ณด (๊ฒฝ์ œ)

Get the Daily Briefing

Pre-market analysis every morning at 6am ET. Free.

Was this article useful?

Anonymous ยท helps us tune the editorial system