Withdrawn and Dormant Accounts Also Leaked
IDs, Passwords, Contact Details, Date of Birth Among Exposed Data
Internal Development Projects and Source Code From TVING Leaked as Well
"Negligent Management of Development and Production Environ

The Ministry of Science and ICT announced the results of the joint public-private investigation team’s probe into the TVing breach incident at the Government Complex Seoul on September 3. Jungkyu Lim, Director of Information Security Network Policy at the Ministry of Science and ICT, is presenting the investigation results. September 3, 2026, Yonhap News Agency.

The Ministry of Science and ICT announced the results of the joint public-private investigation team’s probe into the TVing breach incident at the Government Complex Seoul on September 3. Jungkyu Lim, Director of Information Security Network Policy at the Ministry of Science and ICT, is presenting the investigation results. September 3, 2026, Yonhap News Agency.

View original image

It has been revealed that during the personal information leak incident at the online video service (OTT) TVING in June, information from about 39 million accounts and 361 pieces of technology assets, including source code, were leaked. TVING's lax management of developer access keys led to attackers obtaining core data, including the personal information of all users and development project materials.


The Ministry of Science and ICT announced these findings from the joint public-private investigation team into the personal information leak at TVING on September 3.


The incident began on May 30, when signs of system overload appeared on TVING's database server. TVING discovered that an outsider had gained unauthorized access to its internal server and viewed user information, and reported the breach to the Korea Internet & Security Agency (KISA). Subsequently, on June 2, the Ministry of Science and ICT formed a joint public-private investigation team and launched a full-scale probe.


The investigation found that a total of 39.54 million accounts were leaked—that is, all TVING member accounts were exposed. Since one person can hold multiple accounts, there is duplication in this number. Some individuals had up to 13 accounts. By account type, there were 22.06 million active login-enabled accounts, 8.5 million dormant accounts, 8.87 million withdrawn accounts, and 110,000 test accounts.

TVING's Internal Access Keys Stolen, Data Leaked Overseas... Compensation Worth 20,000 Won Per Person (Comprehensive Report 2) View original image

The leaked information included up to 20 categories (across 70 types), such as: ▲ID ▲password ▲CJ One integrated ID ▲full name ▲mobile phone number ▲email address ▲date of birth ▲linked information (CI) ▲duplicate subscription identification (DI), and more. The CI is a unique value collected as an alternative to resident registration numbers during identity verification to identify individuals.


According to the joint investigation team, the leaked passwords were encrypted, making it impossible to decrypt them into plain text. However, other information such as mobile phone numbers and email addresses, while partly encrypted, could be decrypted since the encryption keys were also leaked.


Further breakdown shows that more information was leaked for accounts with a CI. For 19.04 million CI-holding accounts, which had undergone identity verification, an average of 11.1 data items were leaked. For the 20.4 million accounts without CI, which did not undergo identity verification, an average of 4.6 items per account were leaked.


In addition, all data from the 361 development projects TVING was working on were leaked in this breach. This data amounts to a total of 30.35 gigabytes (GB).


Hacker Stole Developer Environment Access Keys... Information Stolen Without Protection

TVING's Internal Access Keys Stolen, Data Leaked Overseas... Compensation Worth 20,000 Won Per Person (Comprehensive Report 2) View original image

The investigation team explained that the breach occurred after the attacker infiltrated the system by stealing ‘developer environment access keys’ used by TVING developers. The attacker first stole development projects by obtaining the developer environment access keys from a developer.


Subsequently, the attacker also acquired ‘production environment access keys’ stored in source code within the stolen development projects. These keys enabled infiltration of the TVING production environment. During this process, the attacker found that the access credentials (ID and password) for user information databases were stored unencrypted in plain text rather than being encrypted, and stole them as well.


On May 30, the attacker used the stolen database credentials and production environment access keys to attempt to access and extract user data. However, TVING noticed a rapid spike in server activity and cut off the process, foiling the attempt. The next day, the attacker used a production access key with authority to generate virtual servers, created an internal virtual server, and used it as a conduit to extract user information.


Initial Attacker Unknown... Leaked Data Went Overseas


The investigation team stated that they were unable to confirm the identity of the original attacker or exactly how the developer environment access keys were stolen. The police are currently handling the investigation into the TVING attack. Additionally, the investigation team noted that the leaked user data was ultimately transferred abroad.


The team determined that improper management of access keys by TVING left the company exposed to attack. Specifically, access keys needed for both development and production environments were left exposed in source code or stored in plain text without encryption. Additionally, staff members shared these keys with others via the company messenger, and all developers had access rights to all development projects.


Moreover, TVING had already discovered this vulnerability—exposing development and production environment keys in source code—during penetration testing in 2024, but failed to address it.


The investigation team pointed out that TVING did not have an adequate system to detect and respond to attack activity, nor did it implement proper network and system access control policies to manage abnormal access. The dedicated information security staff was also limited to about four members. Jung-gyu Lim, Director of Information Security Network Policy at the Ministry of Science and ICT, said, “The personnel dedicated to information protection is set after consultation and review, compared with similar companies of a comparable size.”


Reporting of the incident also missed the legal deadline. According to the Information and Communications Network Act, incidents must be reported to the Ministry of Science and ICT or KISA within 24 hours of detection, but TVING notified KISA more than 24 hours after awareness. As a result, the ministry plans to impose a fine.


The Ministry of Science and ICT plans to require TVING to submit a follow-up action plan based on the investigation report to prevent recurrence, then monitor implementation and order corrections as needed.


Information Security Investment to Increase Fourfold Compared to Previous Five Years

Tiving executives, including CEO Juhee Choi (second from right), are apologizing for the personal information leak incident at a hotel in Jung-gu, Seoul on September 3, 2026. Photo by Yonhap News

Tiving executives, including CEO Juhee Choi (second from right), are apologizing for the personal information leak incident at a hotel in Jung-gu, Seoul on September 3, 2026. Photo by Yonhap News

View original image

TVING issued an official apology for the personal information leak and announced plans to quadruple information security investment through 2030 compared to the previous five years. For customer compensation, TVING will provide a cyber fraud insurance policy covering financial damages (including cyberfraud) up to 3 million won per person and 5,000 won worth of TVING points, among other compensations.


On the afternoon of September 3, TVING held a briefing on the cyber breach at the Koreana Hotel in Gwanghwamun, Seoul, issuing an official apology and announcing these information security investment and customer compensation plans.


CEO Juhee Choi of TVING stated, "We humbly accept the findings of the joint public-private investigation team, and I sincerely apologize for any concern and unease caused to our customers by this incident." She added, "We will faithfully implement measures to prevent recurrence in order to restore customer trust."


TVING will overhaul its security system following this personal information breach. The company plans to expand investment in information protection and security personnel, and to rebuild its security system on a zero-trust basis. TVING will also restructure organizational governance, foster a stronger security culture, and enhance expertise through external collaboration.


Cyber Fraud & Phishing Safe Insurance... TVING Points and More Provided

Choi Joohee, CEO of Tving, is apologizing for the personal information leak incident at a hotel in Jung-gu, Seoul, on September 3, 2026. Photo by Yonhap News

Choi Joohee, CEO of Tving, is apologizing for the personal information leak incident at a hotel in Jung-gu, Seoul, on September 3, 2026. Photo by Yonhap News

View original image

To restore customer trust and prevent further harm, TVING will provide a compensation package comprising: cyber fraud and phishing insurance, a premium viewing experience upgrade, TVING points, and entertainment coupons.

The insurance will be provided for one year and covers up to 3 million won per person for damages resulting from cyber fraud or phishing, as well as from internet shopping mall or person-to-person transaction fraud. Customers will also automatically receive a premium viewing experience without needing to apply separately.


TVING will grant 5,000 won worth of TVING points for use in purchasing recent movies, and provide an entertainment coupon allowing customers to choose between a one-month Wavve AVOD subscription (5,500 won) or a 5,000 won discount coupon for a CGV combo set (three types).


The compensation package will be available for application from the 7th to the 30th of this month, and will take effect from the 6th of the following month. Further details and application methods are available via notices on TVING’s official app and website.


Yonhap News Agency

Yonhap News Agency

View original image

CEO Juhee Choi: “Compensation to All Withdrawn and Dormant Customers”

TVING estimates the value of the compensation package per person at approximately 20,000 won. In response to questions regarding the financial burden of this leakage, TVING stated, “Of the 19.5 million customers calculated internally after removing duplicates, it is realistically difficult to provide compensation worth 20,000 won per person to all. The compensation package contains components that require cash payments and others based on cost price, with varied options for each, so a flat figure is not accurate.”



CEO Choi added, “It is deeply regrettable and I am very sorry as CEO that TVING must bear a financial burden in its growth as a domestic OTT due to the personal information leak. I believe that content is the most influential factor in enabling customers to trust and enjoy TVING again, and we will strengthen investment in content to pursue global expansion.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing