TVING's Internal Access Keys Stolen, Data Leaked Overseas... Compensation Worth 20,000 Won Per Person (Comprehensive Report 2)
Withdrawn and Dormant Accounts Also Leaked
IDs, Passwords, Contact Details, Date of Birth Among Exposed Data
Internal Development Projects and Source Code From TVING Leaked as Well
"Negligent Management of Development and Production Environ
The Ministry of Science and ICT announced the results of the joint public-private investigation on the Tving breach incident on the 3rd at the Seoul Government Complex. Jeonggyu Lim, Director of Information Protection Network Policy at the Ministry of Science and ICT, is presenting the investigation results. September 3, 2026, Yonhap News Agency. Photo by Yonhap News Agency
View original imageAccording to findings, the personal data breach incident that occurred with the online video service (OTT) TVING in June resulted in the leakage of around 39 million user accounts as well as 361 pieces of technical assets, which included source code. TVING failed to properly manage the access keys used by its developers, which ultimately allowed attackers to gain unauthorized access to sensitive user information and core development project data.
On September 3, the Ministry of Science and ICT announced these results of the joint public-private investigation team regarding the TVING personal information leak.
The incident began on May 30, when abnormal symptoms of system overload appeared on TVING’s database servers. TVING discovered that an external party had accessed its internal servers without authorization and viewed user data, prompting the company to report the breach to the Korea Internet & Security Agency (KISA). Subsequently, the Ministry of Science and ICT formed a joint investigation team on June 2 and launched a full-scale inquiry.
The investigation confirmed that a total of 39.54 million accounts were leaked, encompassing all TVING member accounts. Because one person can have multiple accounts, this figure includes duplicated data; some users held as many as 13 accounts. By account type, the breakdown was: 22.06 million active accounts (capable of logging in), 8.5 million dormant accounts, 8.87 million withdrawn accounts, and 110,000 test accounts.
The leaked information included up to 20 items (across 70 different types), such as: user ID, password, CJ One Integrated ID, name, mobile phone number, email address, date of birth, CI (connection information), and DI (duplicate subscription confirmation information), among others. The CI is a unique value collected in place of the resident registration number during user authentication to identify individuals.
The joint investigation team explained that passwords were leaked only in encrypted form and thus cannot be converted back to plain text. However, other information—such as mobile phone numbers and email addresses—was potentially leaked partly in encrypted form, but because the encryption keys were also leaked, decryption is possible.
Accounts containing CI information experienced more data leakage. Among the 19.04 million accounts with CI (obtained through user authentication), an average of 11.1 items were leaked per account, whereas for the 20.4 million accounts without CI, an average of 4.6 items were leaked per account.
The breach also led to the leakage of all data from 361 ongoing development projects at TVING. This data amounts to a total of 30.35 gigabytes (GB).
Hackers Stole Developer Environment Access Keys—Data Was Left Unprotected
The joint investigation team explained that this data leak occurred after attackers stole the “development environment access keys” used by TVING developers, enabling them to infiltrate TVING’s internal systems. Using the stolen access keys, the attackers first extracted development project data.
The attackers subsequently obtained the “production environment access keys” stored in the source code of the stolen development project. With these keys, they could breach TVING’s production environment. During this process, it was discovered that the database access credentials (ID and password) required to access user information were stored in plain text—not encrypted—which enabled the attackers to steal them as well.
On May 30, the attackers used these database credentials and production environment access keys to attempt access to the user database in order to view and exfiltrate data. TVING detected a sudden spike in server workload and blocked the attempt. The following day, however, the attackers used production environment access keys (with authority to create virtual servers) to set up a virtual server inside the system, which they then used as a conduit to extract user information.
Identity of Initial Attacker Unknown, Leaked Data Transferred Overseas
The joint investigation team stated that it has not yet been able to identify the initial attacker or determine exactly how the developer environment access keys were stolen. The investigation into the TVING attack is currently continuing under the police. In addition, the investigators confirmed that the leaked user data was transferred overseas.
The investigation team determined that TVING was vulnerable to this attack due to improper management of access keys. Access keys required to access development and production environments were exposed in plain text within source code, without encryption. Furthermore, employees sometimes shared these keys with others via internal messenger, and it was revealed that all developers were granted access to all development projects.
Additionally, TVING had identified the vulnerability of exposing access keys within source code during a simulated hacking exercise in 2024, but failed to address the issue.
The joint investigation team also noted that TVING did not have an effective system in place to detect or respond to attacks, nor did it have policies for proper network and system access control. The dedicated information security team consisted of only about four people, indicating clear limitations. Jeonggyu Lim, Director of Information Protection Network Policy at the Ministry of Science and ICT, explained, "The scale of the dedicated security team should be determined in consultation, after comparison with similar-sized companies in similar industries."
TVING also failed to report the breach within the legally required timeframe. Under the Act on Promotion of Information and Communications Network Utilization and Information Protection, notification to either the Ministry of Science and ICT or KISA must occur within 24 hours of recognizing a breach; in TVING’s case, more than 24 hours elapsed before KISA was notified. As a result, the Ministry will impose an administrative fine.
Based on the results of the investigation, the Ministry of Science and ICT plans to require TVING to submit an implementation plan for its recurrence prevention measures. TVING’s follow-through will be monitored, and corrective orders will be issued for any items found deficient.
Information Security Investment to Be Quadrupled Compared to Previous 5 Years
Tving executives, including CEO Juhee Choi (second from right), are apologizing for the personal information leakage incident on the 3rd at a hotel in Jung-gu, Seoul. September 3, 2026. Photo by Yonhap News.
View original imageTVING officially apologized for the data breach and announced plans to increase its information security investment to four times the total of the previous five years, through 2030. As a customer compensation package, TVING will offer peace-of-mind insurance covering up to KRW 3 million in compensation for incidents such as cyber financial fraud, as well as TVING points valued at KRW 5,000.
That day, TVING held a briefing on the cyber breach at the Koreana Hotel in Gwanghwamun, Seoul, where it issued a public apology along with details regarding its information security investment and customer compensation package.
Choi Joohee, CEO of TVING, stated, “We humbly accept the findings of the joint public-private investigation team, and sincerely apologize for the concern and anxiety caused to our customers by this security incident.” She added, “We will responsibly implement all preventive measures to restore customer trust.”
TVING will use this data breach incident as an opportunity to comprehensively reestablish its security framework—increasing both investment in information security and the number of security personnel, and rebuilding its security system based on zero trust principles. It also plans to redefine organizational governance and security culture, and to strengthen expertise through external collaboration.
Peace-of-Mind Insurance for Hacking and Phishing—Distribution of TVING Points, Entertainment Coupons
Choi Joohee, CEO of TVING, is apologizing for the personal information leak incident on the 3rd at a hotel in Jung-gu, Seoul. September 3, 2026. Photo by Yonhap News.
View original imageTo restore customer trust and prevent further damages, TVING will provide a compensation package consisting of: peace-of-mind insurance against hacking and phishing; an upgrade to a premium-quality viewing environment; TVING points; and entertainment coupons.
The insurance will be valid for one year and covers up to KRW 3 million per person not only for losses from cyber financial fraud due to hacking or phishing, but also for internet shopping scams and peer-to-peer transaction fraud. All users will be automatically upgraded to a premium viewing environment without a separate application process.
TVING will offer KRW 5,000 worth of TVING points (which users can use toward individual purchases such as the latest movies), along with an entertainment coupon allowing users to choose one of the following: a one-month Wavve ad-supported video-on-demand (AVOD) subscription (KRW 5,500 value), or a KRW 5,000 discount coupon applicable for a three-item CGV combo.
The compensation package can be requested by users from September 7 to September 30, and will be applied starting on October 6. Further details and application instructions will be available via the official TVING app and website announcements.
CEO Choi Joohee: "Compensation for All Dormant and Withdrawn Users"
TVING estimated the average value of compensation per person for the package at around KRW 20,000. When asked about the financial burden resulting from the breach, the company said, “It would be unrealistic to apply a full compensation of KRW 20,000 per person to our internally estimated 19.5 million unduplicated customers, as the package includes options with different compositions and mixes of cash-like and cost-based compensation elements, making a universal calculation inappropriate.”
Hot Picks Today
"Unable to Continue Mother-Son Relationship": Kim Youngsik Loses First Trial in Annulment Lawsuit Against LG Chairman Kwangmo Koo
CEO Choi stated, “As TVING grows as a domestic OTT platform, it is regrettable and distressing as CEO to face this financial burden from a data breach incident. I believe the greatest driver for regaining customer trust is content, and we plan to further strengthen our content investment to drive global expansion.”
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.