About Twice the Size of Initial Estimates of Damage

Leaked Records Include Dormant and Deactivated Accounts, Increased by Duplicate SNS Registrations

It has been revealed that a total of 39.54 million accounts were involved in the information leak from Tving, the online video service (OTT). This figure far exceeds not only the government’s previously announced provisional estimate of approximately 13 million victims, but also the 19.53 million accounts uncovered by authorities. The higher number is attributed to the leak of all accounts, including dormant and deactivated ones, as well as the influence of Tving's user management system, which allowed multiple registrations through social networking service (SNS) accounts.


According to the joint public-private investigation team under the Ministry of Science and ICT on September 3, a total of 39.54 million accounts were leaked in the Tving breach, meaning all member accounts held by Tving were compromised.


On the 3rd, Jeonggyu Lim, Director of Information Security Network Policy at the Ministry of Science and ICT, announced the investigation results at the Government Complex Seoul. Photo by Yonhap News Agency

On the 3rd, Jeonggyu Lim, Director of Information Security Network Policy at the Ministry of Science and ICT, announced the investigation results at the Government Complex Seoul. Photo by Yonhap News Agency

View original image

The sheer scale of leaked accounts is due to not only currently active Tving memberships but also dormant, deactivated, and even test accounts created for service testing being compromised. Broken down by category, there were 22.06 million active accounts (with login enabled), 8.5 million dormant accounts, 8.87 million deactivated accounts, and 110,000 test accounts. According to Tving’s personal information policy, the data of deactivated members is retained for only five days after deactivation, but if a member made a purchase, their information is stored for up to five years after purchase or refund.


The ability to register multiple times, enabled by Tving’s structure, also contributed to the large number of leaked accounts. Tving currently supports easy SNS sign-up using external accounts such as CJ ONE, Naver, Kakao, Apple, Facebook, and X (formerly Twitter), in addition to Tving’s native registration. This allowed a single user to register multiple times using various third-party accounts.


Analyzing the leaked accounts by registration method, there were 7.26 million registered directly through Tving, 8.63 million using CJ ONE integrated membership, and 22.47 million via SNS sign-up. Thus, more than half were registered through easy sign-up. The investigation team discovered that a single individual could hold up to 13 accounts.


The information compromised in the breach included up to 20 categories (a total of 70 types), such as: ID, password, CJ ONE integrated ID, real name, mobile phone number, email address, date of birth, connection information (CI), and data for duplicate registration verification (DI), among others.


The scope of leaked information varied depending on whether a given account held CI data. CI is a unique value collected in place of the resident registration number during identity verification to identify individuals. For 19.04 million accounts with CI, an average of 11.1 data fields were leaked. For the 20.4 million accounts without CI, an average of 4.6 items were leaked. Accounts without CI, which did not undergo identity verification, often had missing or inaccurate information such as name, contact details, or email address.



However, the exact scale of personal information leakage will be confirmed following an investigation by the Personal Information Protection Commission, not by the joint investigation team. In accordance with the Personal Information Protection Act, the Commission calculates the scale of damages based on the number of data subjects, not the number of leaked accounts. As such, the Commission is expected to estimate the actual number of affected users by excluding duplicate registrations from the leaked account numbers. The final decisions on penalties and measures, including fines, will also be determined by the Commission.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing