Key facts
- Nearly 40 million Tving user accounts were compromised in a data breach.
- The breach stemmed from a hacking incident reported in June.
- Exposed data includes names, dates of birth, phone numbers, and email addresses.
- An unidentified hacker stole a developer's access key to infiltrate Tving's systems.
- Tving has since strengthened its security measures.
Nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach following a hacking incident in June. The Ministry of Science and ICT announced the findings of a three-month investigation, revealing that 39.54 million accounts and 361 technical assets, including source code, were affected.
The compromised accounts include those registered directly with Tving, CJ ONE integrated memberships, and those created via social media log-ins from platforms like Naver, Kakao, Facebook, Apple, and X. Of the total, 22.06 million were active accounts and 17.37 million were inactive. The leaked data spans 20 categories and 70 types, including names, birth dates, mobile numbers, and email addresses, with the extent varying by registration method.
Investigators determined that an unidentified hacker gained access by stealing a developer's access key. Tving is also facing a potential fine for delaying its report of the incident to the Korea Internet & Security Agency. The Personal Information Protection Commission will separately assess the breach and decide on penalties.
Authorities warned of potential secondary damages, such as smishing and voice phishing, using the leaked personal information. The breach could impact Tving's improving financial performance, as the platform recently posted its first quarterly operating profit since becoming a standalone company in 2020.
