Nearly 40 Million Tving User Accounts Compromised in Data Breach
Quick Look
A joint investigation revealed that nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a data breach reported in June, involving 39.54 million accounts and 361 technical assets, with the breach stemming from a stolen developer access key and delayed reporting to authorities.
AI-generated summary
Why It Matters
Tving is an online video streaming platform operated by CJ ENM Co. It became a standalone company in 2020 and reported its first quarterly operating profit in Q2 2024.
By Kim Eun-jung
SEOUL, Sept. 3 (Yonhap) -- Nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach stemming from a hacking incident reported in June, a joint investigation showed Thursday.
The Ministry of Science and ICT announced the results of a three-month government-civilian investigation into the breach at Tving, an online video streaming platform operated by entertainment giant CJ ENM Co.
A total of 39.54 million user accounts and 361 technical assets, including source code, were found to have been compromised in the breach reported on June 1, although the account figure includes multiple accounts held by the same users, the ministry said.
Tving has since strengthened its security measures, and no signs of additional attacks have been detected so far, it noted.
By registration method, they included 7.26 million accounts registered directly with Tving, 8.63 million CJ ONE integrated membership accounts and 22.47 million accounts created through social media log-in services, including Naver, Kakao, Facebook, Apple and X.
Of the total, 22.06 million were active accounts that could be used to log in, while 17.37 million were inactive accounts, including dormant and closed accounts.
The leaked information covered 20 categories comprising 70 types of data, including names, dates of birth, mobile phone numbers, email addresses and connecting information, though the type and extent of information exposed varied depending on how users registered their accounts.
The Personal Information Protection Commission is expected to separately determine the extent of the personal data breach and decide on the amount of penalties.
Investigators found that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems.
The investigation also found that Tving failed to report the breach to the Korea Internet & Security Agency within 24 hours of detecting the incident on May 30, reporting it only on June 1 and potentially facing a fine for the delay.
Investigators warned of potential secondary damage, saying the hacker could exploit the compromised data to carry out further attacks, while leaked personal information could be used for cybercrimes such as smishing and voice phishing.
The breach could deal a setback to Tving at a time when the streaming platform has begun to improve its financial performance.
Tving posted 140.7 billion won (US$103.6 million) in sales and 6 billion won in operating profit in the second quarter, marking its first quarterly operating profit since becoming a standalone company in 2020.
What to Watch
AI outlook — possibilities, not facts
The Personal Information Protection Commission will impose financial penalties on Tving for the data breach.
Very likely · Within weeks
Tving will face increased scrutiny from regulators regarding its data security practices.
Likely · Within months
Open Questions
- What specific penalties will the Personal Information Protection Commission impose?
- Was the stolen developer access key recovered or rotated?
- Have any instances of smishing or voice phishing using the leaked data been detected?







