Tving Suffers Breach of 39.54 Million Accounts... Up to 20 Data Items Leaked Per Account
Withdrawn and Dormant Accounts Also Compromised
ID, Password, CI, Contact Information, and Date of Birth Among Leaked Data
Tving's Internal Development Projects and Source Code Exposed
"Negligent Management of Development and Production E
It has been revealed that the number of accounts compromised in the online video service (OTT) TVING's personal information leak incident in June reached about 39 million. The leaked personal information included up to 20 data items (from a total of 70 types) per account, such as names, contact information, emails, and connected information (CI).
On September 3, the Ministry of Science and ICT announced the findings of the public-private joint investigation team (hereafter "the investigation team") regarding the breach of personal information at TVING.
The investigation confirmed that a total of 39.54 million accounts (including duplicates) were leaked. By account type, there were 22.06 million active accounts (accounts that can be logged into), 8.5 million dormant accounts, 8.87 million withdrawn accounts, and 110,000 test accounts. In terms of registration method, 7.26 million were TVING direct sign-ups, 8.63 million were CJ ONE integrated member accounts, and 22.47 million were signed up through social networking service (SNS) integrations.
The information leaked through the security breach included as many as 20 data items, such as: ID, password (one-way encrypted), CJ ONE integrated ID, full name, mobile phone number, email address, date of birth, connected information (CI), and duplicate subscription verification information (DI). CI, a unique value used to identify individuals, is collected in place of the resident registration number during identity verification processes. The investigation team explained that although passwords were leaked, they were encrypted and cannot be decrypted as plain text.
The breach also resulted in the leak of TVING's development projects. According to the investigation team, the attacker stole all 361 development projects, which included source code stored within TVING’s internal system. The total leaked development data amounted to 30.35GB. These development projects contained technical assets such as personalized content recommendation and search algorithms, user management and authentication systems, payment management, and the operation of paid services.
The investigation team stated that the breach occurred after the attacker infiltrated the system by stealing the "development environment access key" used by TVING’s developers. Using the stolen development environment access key, the attacker exfiltrated all 361 development projects.
Subsequently, the attacker also stole the "production environment access key" stored in the source code of the leaked development projects, along with the access credentials (ID and password) needed to reach the user information database. The perpetrator then exploited these obtained production environment access keys and credentials to further leak user data.
The investigation team determined that TVING was vulnerable to attack because it failed to manage access keys appropriately. Furthermore, while TVING identified the vulnerability of exposing development and production environment access keys within source code during penetration testing in 2024, it did not rectify the issue.
The investigation team also found that TVING lacked effective mechanisms to detect and respond to malicious activities and did not establish network and system access control policies to restrict abnormal access. The investigative report pointed out that TVING had a dedicated information security staff of only about four people, which was also seen as a limitation.
TVING’s notification of the breach also exceeded the legal deadline. Under the Network Act, a data breach must be reported to the Ministry of Science and ICT or KISA within 24 hours of its discovery. However, TVING reported the incident to KISA more than 24 hours after becoming aware of the breach. The Ministry of Science and ICT has decided to impose a fine in accordance with this violation.
Hot Picks Today
Cracks in Samsung and SK hynix’s Duopoly?... Micron’s Bet with the ‘100,000 HBM Wafers’ Bomb [ChipTalk]
- "This Is the Must-Visit Spot for Foreigners in Korea—Not Olive Young or Daiso... How Foreign Tourists Are Changing the Profit Formula [Weekend Money]"
- Will the Exchange Rate Drop Below 1,300 Won by Year-End?... Exploring the Causes [Weekend Money]
- "China Strikes Back With Sharp Visa Fee Hike for Japanese Nationals"
- "Age Is Not a Free Pass": The Reason for Shock After Watching the CCTV Footage
Based on the joint investigation team’s findings, the Ministry of Science and ICT plans to require TVING to submit an action plan for recurrence prevention. The Ministry will then monitor TVING’s compliance and order corrective actions if any deficiencies remain.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.