ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Yes24 faces security incident causing website and app outage

South Korea’s largest ticketing platform Yes24 said it suffered a security incident that affected the company’s website and mobile app, rendering it inaccessible. 

 

Headquartered in Seoul, South Korea, Yes24, is an internet-based book, music CD, and ticket distributor that caters to more than 20 million registered users.

 

Recently, local media reported that Yes24 became a victim of a significant cyber attack around June 9 that left the company’s official website and application inaccessible, crippling online bookings for concerts, e-book access and community forums. 

 

The company said it had launched an investigation and involved eternal cyber security experts, to determine the nature and scope of the incident. Yes24 added that it aims to restore full operations by June 15.

 

“First of all, we sincerely apologise for the inconvenience caused by this service failure.

Currently, we are in the process of normalising some services including Sarak, Channel Yes, Yeongjungmun Mall, and SCM/USCM.

 

“Yes24 will issue individual notifications if further investigations confirm any personal data exposure,” the company said on the website.

 

The outage has caused a ripple effect of disruptions, leading to the postponement or cancellation of pre-sales and events for major K-pop artists and actors, including Park Bo-gum, Enhypen, Ateez, and rapper B.I.

 

In an update on its website, Yes24 said that it has regained control of its administrator account and services including books, records/DVDs, stationery, gifts, and tickets are now available for purchase. 

 

Acknowledging the reports of the security incident, South Korea’s national data protection authority, the Personal Information Protection Commission said it has initiated a formal investigation into the incident. The authorities said it will verify whether Yes24 met its legal obligations under the country’s data privacy laws.

 

In recent times, South Korean businesses have become a vulnerable target for hackers. Last month, Christian Dior and Tiffany & Co, both owned by LVMH, disclosed data security incidents affecting its South Korean customers. 

 

In both incidents, the threat actors stole sensitive customer data including names, gender, phone numbers, email addresses, mailing addresses, purchase amounts, and shopping preferences, however, threat actors did not access financial data such as bank account numbers, IBANs, or credit card information. 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543