Computers

Barunson M Card Discloses Possible Data Breach After Database Intrusion

Barunson Company says an external attacker accessed its database and altered wedding invitation titles; customer names, phone numbers and bank account details may be affected.

Barunson Company has notified customers of a possible personal data breach affecting the Barunson M Card mobile wedding invitation service, according to etnews.com. The company confirmed on October 7, 2026 that an external attacker had illegally accessed its database and altered invitation titles between November and December of the previous year.

The company said data from mobile invitations created through Barunson Card, Barunson Mall, Premier Paper, The Card and Be Hands Card between 2016 and 2021 may have been affected.

Potentially exposed items include the names, phone numbers and relation of grooms, brides and hosts, as well as bank name, account number and account holder for wedding gift accounts. Baby names, birthdays and parents' names and phone numbers entered in first-birthday invitations were also listed as potentially exposed.

Barunson Company reported the incident to KISA and the Personal Information Protection Commission. The company plans to remove the inserted strings from its database, check security vulnerabilities, strengthen account security, invalidate authentication codes and block access to mobile invitation-related data.

Earlier intrusion altered invitation titles

Between November and December 2025, an external attacker illegally accessed the company's database and altered invitation titles, the company said.

Quick answers

Which Barunson services are affected by the possible data breach?

Invitations created via Barunson Card, Barunson Mall, Premier Paper, The Card and Be Hands Card between 2016 and 2021 may be affected.

What personal data may have been exposed?

Names, phone numbers and relation of grooms, brides and hosts, bank name, account number and account holder for wedding gift accounts, plus baby names, birthdays and parents' names and phone numbers from first-birthday invitations.

What has Barunson Company done about the incident?

It reported the incident to KISA and the Personal Information Protection Commission and plans to remove the inserted strings, check security vulnerabilities, strengthen account security, invalidate authentication codes and block access to mobile invitation-related data.

Source