
A joint government-civilian investigation reveals that 39.54 million Tving user accounts were compromised in a June hacking incident.
Nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach following a June hacking incident, a joint investigation showed.
AI-generated summary
Tving recently posted its first quarterly operating profit since becoming a standalone company in 2020, driven by streaming rights for South Korea's professional baseball league.
By Kim Eun-jin
SEOUL, Sept. 3 (Yonhap) -- Nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach stemming from a hacking incident reported in June, a joint investigation showed Thursday.
The Ministry of Science and ICT announced the results of a three-month government-civilian investigation into the breach at Tving, an online video streaming platform operated by entertainment giant CJ ENM Co.
A total of 39.54 million user accounts and 361 technical assets, including source code, were found to have been compromised in the breach reported on June 1, although the account figure includes multiple accounts held by the same users, the ministry said.
Tving has since strengthened its security measures, and no signs of additional attacks have been detected so far, it noted.
By registration method, they included 7.26 million accounts registered directly with Tving, 8.63 million CJ ONE integrated membership accounts and 22.47 million accounts created through social media log-in services, including Naver, Kakao, Facebook, Apple and X.
Of the total, 22.06 million were active accounts that could be used to log in, while 17.37 million were inactive accounts, including dormant and closed accounts.
The leaked information covered 20 categories comprising 70 types of data, including names, dates of birth, mobile phone numbers, email addresses and connecting information, though the type and extent of information exposed varied depending on how users registered their accounts.
The Personal Information Protection Commission is expected to separately determine the extent of the personal data breach and decide on the amount of penalties.
Investigators found that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems.
Lim Jeong-gyu, director general for the ministry's information security and network policy, said the investigation team has yet to identify the attacker, adding that a police investigation is underway.
Lim said the stolen data was transferred to accounts located overseas, but authorities have yet to determine where the attacker was based. He said the police investigation is expected to help identify the country from which the attack originated.
The investigation also found that Tving failed to report the breach to the Korea Internet & Security Agency within 24 hours of detecting the incident on May 30, reporting it only on June 1 and potentially facing a fine for the delay.
Investigators warned of potential secondary damage, saying the hacker could exploit the compromised data to carry out further attacks, while leaked personal information could be used for cybercrimes, such as smishing and voice phishing.
The latest incident adds to a series of major personal data breaches over the past year involving South Korean companies, including mobile carriers SK Telecom Co. and KT Corp., as well as U.S.-listed e-commerce giant Coupang.
The breach could deal a setback to Tving at a time when the streaming platform has begun to improve its financial performance, helped by its exclusive digital streaming rights to South Korea's professional baseball league, secured through parent company CJ ENM.
Tving posted 140.7 billion won (US$103.6 million) in sales and 6 billion won in operating profit in the second quarter, marking its first quarterly operating profit since becoming a standalone company in 2020.
Following the announcement, Tving CEO Choi Ju-hee apologized for the personal data breach and pledged to cooperate fully with the investigation.
"We humbly accept the investigation results of the government-civilian joint team and will responsibly implement corrective measures and steps to prevent a recurrence," Choi said at a press briefing.
Tving said it has taken emergency security measures since the breach and developed mid- and long-term cybersecurity plans to strengthen its systems and restore customer trust, pledging to quadruple its cybersecurity investment over the next five years.
As compensation for affected customers, Tving said it will offer one year of hacking and phishing insurance coverage, upgraded streaming benefits, 5,000 won in platform credits and a choice of entertainment coupons.
AI outlook โ possibilities, not facts
Personal Information Protection Commission will determine penalties.
Very likely ยท Within weeks
Police investigation will identify the hacker's origin country.
Likely ยท Within months

Nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach in June, a joint government-civilian investigation revealed Thursday, exposing personal information and source code.

LG Electronics announced it will showcase around 150 personalized AI-powered products, including the new ThinQ Clo autonomous AI agent, at the IFA 2026 trade show in Berlin.

A joint investigation revealed that nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a data breach reported in June, involving 39.54 million accounts and 361 technical assets, with the breach stemming from a stolen developer access key and delayed reporting to authorities.

A consortium led by Naver Cloud Corp. has been selected by South Korea's Ministry of Science and ICT to develop an AI foundation model specialized in cybersecurity, beating a rival SK Telecom-led group. The project will provide up to 256 Nvidia B200 GPUs over 10 months to build a sovereign AI model tailored to South Korea's security environment amid rising cyber risks from evolving AI technologies.

๋ฏธ๊ตญ ๋ฒ์ง๋์์ฃผ ์๋ ์ฐ๋๋ฆฌ์ ์ฐ๋ฐฉ๋ฒ์์ด ๋ฒ๋ฌด๋ถ๊ฐ ์ฒญ๊ตฌํ ๊ตฌ๊ธ์ ์จ๋ผ์ธ ๊ด๊ณ ๊ฒฝ๋งค ํ๋ซํผ ์ ๋์์ค(AdX)์ ๋ํ ๊ฐ์ ๋งค๊ฐ ์๊ตฌ๋ฅผ ๊ธฐ๊ฐํ๊ณ , ๊ฒฝ์์ฌ์ ์ค์๊ฐ ์ ์ฐฐ ์ ๊ทผ ๊ถํ ๋ถ์ฌ ๋ฑ ํ๋์ ๊ตฌ์ ์ฑ ์ ์ฑํํ๋ค. ์ด์ ๋ฐ๋ผ ๊ตฌ๊ธ์ ํฌ๋กฌ ๊ฐ์ ๋งค๊ฐ ์์ก์ ์ด์ด ๊ด๊ณ ์ฌ์ ๋ถํ ์๊ธฐ๋ ํผํ๊ฒ ๋๋ค.

UNIST ๊ถํํ ๊ต์ํ์ด ์๊ตญ ์ผ์๋ธ๋ฆฌ์ง๋์ ๊ณต๋์ผ๋ก ๋ฎ์๋ ํ๋น์ฉ, ๋ฐค์๋ ์ค๋ด์กฐ๋ช ์ฉ์ผ๋ก ์กฐํฉ์ ๋ฐ๊ฟ ์จ์ข ์ผ ์ถฉ์ ํ ์ ์๋ ๋ชจ๋ํ ๊ด ์ถฉ์ ๋ฐฐํฐ๋ฆฌ ๊ตฌ์กฐ๋ฅผ ๊ฐ๋ฐํ๋ค.