Leak of 39.54 Million Accounts (Including Duplicates)
Tving Offers Compensation Package Worth KRW 20,000 per Person

TVING, a domestic online video service (OTT) provider, has officially apologized for a data breach affecting 39.54 million accounts (including duplicates) and announced that it will quadruple its information security investments by 2030 compared to the previous five years. As a compensation plan, TVING will offer a safety insurance policy covering up to KRW 3 million for incidents such as cyber financial fraud, and a compensation package worth approximately KRW 20,000 per person, including a KRW 5,000 TVING point.

◆ Compensation Package Worth KRW 20,000 Per Person for 39.54 Million Accounts Leaked

[Why&Next]The First Female OTT CEO Bows Her Head…Why Tving Struggled Over Its Compensation Package View original image

At a ‘Cyber Incident Briefing’ held at Koreana Hotel in Gwanghwamun, Seoul, on the afternoon of September 3, CEO Juhee Choi, dressed in a black suit, repeatedly offered apologies to customers with a somber expression.


CEO Choi stated, “We sincerely accept the findings of the government-private joint investigation team and deeply apologize to our customers for the concern and anxiety this incident has caused. We will take responsible measures to implement preventive actions and restore customers' trust.”


The company bears significant responsibility for the breach, as TVING failed to implement basic security measures, thereby amplifying the scale of damage. According to the government-private joint investigation team under the Ministry of Science and ICT, the breach occurred due to improper management of access keys for critical systems at TVING. The leaked account information encompasses all of TVING’s members, totaling 39.54 million, which is twice the previously reported figure of 19.53 million accounts.


The incident began when an attacker stole a ‘development environment access key’ used by TVING developers. This access key allowed entry into development projects. However, even after investigation, authorities could not determine exactly how the attacker obtained this key. The attacker subsequently extracted the ‘operational environment access key’ from the source code stored within the development project, and ultimately acquired the IDs and passwords needed to access the user information database in the operational environment, resulting in the mass leakage of account data.

◆ Deciding Compensation Despite KRW 69.8 Billion in Operating Losses to Prioritize Trust

Amid Netflix’s continued dominance, TVING has sought to solidify its position as a domestic OTT provider and reportedly faced significant internal debate over compensation plans. Last year, TVING posted KRW 406 billion in revenue, with KRW 69.8 billion in operating losses. The compensation package of roughly KRW 20,000 per person will directly add to this year’s financial burdens.


It is said that CEO Choi, facing a difficult situation, chose to prioritize customer trust above all and proceeded with the compensation plan. As the first female CEO in Korea’s OTT industry, Choi has experience at Boston Consulting Group (BCG) as well as at The Walt Disney Company Korea, where she oversaw Asia and Korea business strategies, known for her strong planning and execution skills. CEO Choi’s crisis management is credited with gradually increasing TVING’s Monthly Active Users (MAU) to 8.5 million as of July.

On September 3, 2026, Choohee Choi, CEO of TVING, apologized for the personal information leak incident at a hotel in Jung-gu, Seoul. Photo by Yonhap News.

On September 3, 2026, Choohee Choi, CEO of TVING, apologized for the personal information leak incident at a hotel in Jung-gu, Seoul. Photo by Yonhap News.

View original image

CEO Choi added, “I feel sad and sorry that this data breach incident has resulted in a financial burden for TVING as we grow as a domestic OTT provider. I believe content is the most powerful driver for regaining customers’ confidence and enjoyment of TVING. We will further strengthen our investment in content and aim for global expansion.”


The exact final scale of the data breach and any fines are to be determined by the Personal Information Protection Commission. The commission launched an immediate investigation following a personal data breach report from TVING on June 3. Under the Personal Information Protection Act, the commission assesses the damage based on the number of individuals affected, not the number of accounts. Therefore, the actual number of impacted users is calculated by excluding duplicate accounts from the total leaked account information.


The Ministry of Science and ICT announced it intends to impose an administrative fine of up to KRW 30 million on TVING for failing to report the breach within the statutory period after becoming aware of the incident. Separately, any additional fines, such as penalties, will be determined by the Personal Information Protection Commission.



According to the pre-revised Personal Information Protection Act, up to 3% of the three-year average revenue prior to the breach may be imposed as a penalty. Based on this, TVING could face penalties of up to KRW 11.7 billion. An official from the commission commented, “The investigation is ongoing, and it is difficult at this point to predict when it will be completed and when the penalties will be decided. Once the investigation is finished, it will be released separately.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing