Withdrawn and Dormant Accounts Also Compromised
Includes IDs, Passwords, CI, Contact Information, Date of Birth, and More
TVING's Internal Development Projects and Source Code Leaked
"Negligence in Managing Development and Production Enviro

In the June data breach incident involving online video streaming (OTT) platform TVING, it was revealed that approximately 39 million user accounts and 361 technical assets, including source code, were leaked. The breach occurred because TVING neglected access key management used by developers, resulting in the exposure of all user personal information and critical data such as development projects to the attacker.


On September 3, the Ministry of Science and ICT announced the findings of the joint public-private investigation team into the TVING data breach incident.


The incident began on May 30, when unusual signs of system overload were detected on TVING's database (DB) server. TVING discovered that an unauthorized external party had accessed internal servers and viewed user data, which prompted them to report the breach to the Korea Internet & Security Agency (KISA). On June 2, the Ministry of Science and ICT formed a joint investigation team to launch a full-scale probe.

39.54 Million Accounts Leaked...ID, Password, CI, Name, Contact Details Exposed

A total of 361 technical assets including source code and approximately 39.54 million user accounts were confirmed to have been leaked from the online video service (OTT) platform Tving. On the 3rd, the Ministry of Science and ICT announced the results of the joint government-private investigation into the Tving breach incident at the Government Complex Seoul. On the 3rd, Jeongkyu Lim, Director of Information Protection and Network Policy at the Ministry of Science and ICT, announced the investigation results at the Government Complex Seoul. Photo by Yonhap News

A total of 361 technical assets including source code and approximately 39.54 million user accounts were confirmed to have been leaked from the online video service (OTT) platform Tving. On the 3rd, the Ministry of Science and ICT announced the results of the joint government-private investigation into the Tving breach incident at the Government Complex Seoul. On the 3rd, Jeongkyu Lim, Director of Information Protection and Network Policy at the Ministry of Science and ICT, announced the investigation results at the Government Complex Seoul. Photo by Yonhap News

View original image

The investigation found that a total of 39.54 million accounts were leaked, effectively exposing all TVING member accounts. Since a single user could hold multiple accounts, the figure includes duplicates; in some cases, a single person held up to 13 accounts. By account type, the breakdown was 22.06 million active accounts (login-enabled), 8.5 million dormant accounts, 8.87 million withdrawn accounts, and 110,000 test accounts.


Classified by sign-up method, 7.26 million were direct TVING sign-ups, 8.63 million were CJ ONE integrated members, and 22.47 million were registered via SNS (social network services). TVING supports registrations using accounts from Naver, Kakao, Facebook, Apple, and X (formerly Twitter), among others.


The leaked data encompassed up to 20 categories (70 types) of information, including: ▲ID ▲password ▲CJ ONE integrated ID ▲full name ▲mobile phone number ▲email address ▲date of birth ▲connection information (CI), and ▲duplicate sign-up verification info (DI), among others. CI (Connection Information) is a unique value used for personal identification and is collected during verification processes instead of a resident registration number.


The investigation team explained that the leaked passwords were encrypted and could not be decrypted into plain text. However, other details like mobile phone numbers and email addresses, although also partially encrypted, could potentially be decrypted as the decryption key was also leaked.


By account type, those with CI had higher levels of information exposure. Accounts with CI, which had gone through identity verification, saw an average of 11.1 types of data leaked, while accounts without CI averaged 4.6 types of information exposure.


This breach also resulted in the leak of complete data for all 361 development projects TVING was working on, totaling 30.35 gigabytes (GB). The compromised projects included user-customized content recommendation and search algorithms, user management and authentication systems, payment processing, and paid service operation technologies.


The specific scale of personal information leaked will be determined after further investigation by the Personal Information Protection Commission. Any penalties or fines related to the personal data leak will be decided by the Commission as well.

Hackers Stole Developer Access Keys... Two Types of Keys and DB Credentials Left Unprotected

39.54 Million TVING Accounts Leaked: Internal Access Keys Stolen, User Data Sent Overseas (Comprehensive) View original image

The joint investigation team explained that the breach occurred when the attacker infiltrated TVING's internal systems by stealing the "development environment access keys" used by its developers. The attacker first stole these keys to extract development project data.


The attacker then obtained the "production environment access keys" stored within the source code of the stolen development projects, granting access to TVING’s production environment. During this process, the attacker found the connection information (ID and password) for the user information database stored in plain text without encryption, and stole this information as well.


On May 30, the attacker used the stolen database credentials and production environment access keys to attempt access to the user DB for data retrieval and exfiltration. However, TVING detected the sharp rise in server workload and blocked the operation, causing the initial attempt to fail. The following day, the attacker used a production environment access key with permissions to create virtual servers, established a virtual server within the environment, and exfiltrated user data through this newly created server.

Original Attacker Unidentified...Exfiltrated Data Sent Overseas

The investigation team stated that the original attacker and the method used to steal the development environment access keys remain unidentified. The police are currently investigating the individual(s) responsible for the TVING breach. Additionally, the team noted that the leaked user data was transferred overseas.


The investigation team determined that TVING’s mismanagement of access keys left them vulnerable to attack. Access keys required for entry into development and production environments were exposed within source code or stored in plain text without encryption. Employees also shared these keys with others via internal messenger, and all developers were given rights to access every development project.


Furthermore, TVING discovered a vulnerability in a 2024 penetration test in which development and production environment access keys were exposed in source code but did not address or correct the issue.


The investigation team also explained that TVING lacked a proper detection and response system for attacks, and failed to establish network and system access control policies to manage suspicious access. There were also only around four dedicated information security staff, which the investigation team described as insufficient. Jeongkyu Lim, Information Security Network Policy Officer at the Ministry of Science and ICT, explained, "The number of information security staff is determined after comparing with companies of similar size and industry characteristics, followed by consultation and review."


TVING also failed to meet the regulatory reporting deadline after the breach occurred. Under the Information and Communications Network Act, a breach must be reported to the Ministry of Science and ICT or KISA within 24 hours of discovery, but TVING reported the incident to KISA more than 24 hours after detection. Consequently, the Ministry plans to impose an administrative fine.


Based on the investigation results, the Ministry of Science and ICT will require TVING to submit an action plan for recurrence prevention. The Ministry will then monitor TVING’s progress and order corrections for any outstanding issues needing improvement.



Meanwhile, TVING is scheduled to hold an official apology and explanatory session this afternoon regarding the cyber breach incident. CEO Choi Juhui and key management personnel will attend to offer an official apology, outline future plans to strengthen information security, and provide details on customer compensation measures.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing