TechNewsReel
Live

Musinsa-owned 29CM exposes 160,000 customer records in API breach

South Korean authorities have launched a probe into the curated fashion platform after a security vulnerability leaked sensitive user data.

TechNewsReel Newsroom · August 30, 2026

The curated fashion platform 29CM has suffered a significant data breach that exposed the personal information of approximately 160,000 customers. The incident has drawn immediate regulatory scrutiny from South Korean authorities as the company works to notify affected users.

According to reports from ChosunBiz, the breach resulted in the exposure of roughly 160,000 customer records. The security failure was linked to a vulnerability within the platform's API, which allowed unauthorized access to sensitive data. Following the discovery, South Korean authorities launched a probe into the incident to determine the full extent of the exposure and evaluate the company's security protocols.

The Musinsa Expansion

29CM operates as a curated fashion and lifestyle marketplace and is a subsidiary of Musinsa, South Korea's largest fashion unicorn. Musinsa acquired the platform as part of a broader strategic effort to diversify its market reach and integrate a more curated shopping experience into its ecosystem. This acquisition has positioned Musinsa as a dominant force in the regional e-commerce landscape, consolidating various fashion niches under one corporate umbrella.

Risks of Rapid Scaling

This breach underscores the persistent cybersecurity vulnerabilities that plague rapidly scaling e-commerce platforms. As companies like Musinsa aggressively expand through acquisitions and platform integration, the attack surface for potential hackers grows. The consolidation of massive amounts of consumer data under a single corporate entity creates a high-value target, where a single API flaw can lead to the compromise of hundreds of thousands of user profiles.

Regulatory Outlook

Industry observers are now watching how South Korean regulators will penalize the lapse, as the government has tightened data protection laws in recent years. While the core cause has been identified as an API vulnerability, it remains to be seen if the breach was the result of a targeted attack or a systemic failure in the platform's development lifecycle. Further details regarding the specific types of data leaked—such as payment information or encrypted passwords—remain under investigation by the authorities.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.