
Security vulnerabilities in APIs (Application Programming Interfaces) are emerging in recent personal information breach (hacking) incidents involving fashion platform Musinsa, beauty and plastic surgery information platform Gangnam Unni, and fan platform Weverse. As hacking cases through APIs used for connecting platforms or service partnerships continue to be reported, experts are calling for strengthened security measures tailored to these risks.
According to the information and communications industry and the Personal Information Protection Commission (PIPC) on the 28th, recent hacking incidents involving △Musinsa (29CM), △Gangnam Unni (Healing Paper), and △Weverse all share a common characteristic: personal information was leaked through APIs. In the Gangnam Unni hacking incident that occurred on the 4th, hackers exploited vulnerabilities in an API used to view web service consultation records. Musinsa was found to have been attacked via its member order information API. Weverse is also under investigation by authorities after hackers accessed payment-related APIs and leaked personal information.
APIs, primarily used to connect platforms or services, serve as actual conduits for the exchange of real personal information. According to traffic data aggregated by Cloudflare, a traffic management service, 57% of all internet service traffic flows through APIs. Consequently, in recent hacking incidents, hackers have been identified as requesting information like legitimate users to collect personal information from multiple users via APIs.
The PIPC warns that inadequate API management can make systems prime targets for hacking. Hackers mimic normal API requests to exploit security vulnerabilities such as unauthorized access to personal information lookup permissions or excessive call frequencies. The commission explains that if login credentials are verified but proper checks on personal information lookup permissions are omitted, or if unnecessary personal information is included in response data from a single request, it can lead to large-scale personal information leaks.
In particular, when APIs process personal information, data not visible to website users may also be transmitted. Experts note that even if a customer enters only their name on a webpage to purchase a product, connected data characteristics allow personal information such as email addresses, phone numbers, and addresses to move along with the transaction. Other identified issues include: △the potential for increased scale of personal information leaks due to automated attacks via programs like AI (artificial intelligence); △security vulnerabilities arising from failure to delete or manage unused APIs; and △negligence in permission management following personnel changes such as transfers or resignations.
To address these vulnerabilities, the PIPC has recommended that businesses utilizing APIs: △adhere to the principle of data minimization from the design stage; △grant and manage API permissions in accordance with the principle of least privilege; and △identify, update, and regularly audit lists of active APIs. Additionally, businesses operating services using provided APIs have been instructed to verify whether response data includes personal information unrelated to their services and to immediately remove any unnecessary personal information.
Professor Im Jong-in of Korea University's Graduate School of Information Security advised, "As we transition into the agentic AI era, the movement of information via APIs will inevitably increase, along with the risk of security incidents." He further stated, "Companies handling personal information must also actively consider implementing appropriate guardrails (guidelines defining prohibited behaviors) during information transfers via APIs and adopting advanced technologies such as anomaly detection systems leveraging AI."