South Korean Probe Finds 39.54 Million Tving Accounts Compromised in Data Breach
Probe finds 39.54 million Tving accounts compromised; names, phones, emails leaked; Tving faces possible fine.
The Ministry of Science and ICT said 39.54 million user accounts and 361 technical assets, including source code, were affected in the breach first reported June 1, although the figure includes people who held multiple accounts. Tving, the online video streaming service operated by entertainment conglomerate CJ ENM Co., has since strengthened security and no additional attacks have been detected, the ministry said.
By registration method, the compromised accounts included 7.26 million registered directly with Tving, 8.63 million CJ ONE integrated-membership accounts and 22.47 million accounts created through social media log-in services such as Naver, Kakao, Facebook, Apple and X. Of the total, 22.06 million were active accounts that could be used to log in, while 17.37 million were inactive accounts, including dormant and closed accounts.
The leaked information covered 20 categories comprising 70 types of data, including names, dates of birth, mobile phone numbers, email addresses and connecting information. The type and extent of exposed data varied depending on how users registered their accounts, investigators said.
Investigators found that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems. Lim Jeong-gyu, the ministry's director general for information security and network policy, said the investigation team has not yet identified the attacker. Stolen data was transferred to accounts located overseas, and a police investigation is under way to determine where the attack originated.
The investigation also found that Tving failed to report the breach to the Korea Internet & Security Agency within 24 hours of detecting the incident on May 30, reporting it only on June 1 and potentially facing a fine for the delay. The Personal Information Protection Commission is expected to separately determine the extent of the personal data breach and decide on penalties. Investigators warned of potential secondary damage, saying the hacker could use the stolen material for further attacks or for smishing and voice phishing.
The breach is the latest in a series of large personal data incidents involving South Korean companies over the past year, including mobile carriers SK Telecom Co. and KT Corp. and e-commerce giant Coupang. It also comes as Tving begins to improve its financial performance; the streaming platform posted 140.7 billion won (US$103.6 million) in sales and 6 billion won in operating profit in the second quarter, its first quarterly operating profit since becoming a standalone company in 2020, helped by exclusive digital streaming rights to South Korea's professional baseball league.
After the ministry announcement, Tving CEO Choi Ju-hee apologized for the breach and pledged full cooperation with the investigation. Tving said it has taken emergency security measures since the breach and developed medium- and long-term cybersecurity plans, pledging to quadruple security investment over the next five years. It will provide affected customers with one year of hacking and phishing insurance coverage, upgraded streaming benefits, 5,000 won in platform credits and a choice of entertainment coupons.