AI Automated Translation.

Font Size

Share

'39.54 Million Accounts Leaked': Tving Ignored Known Security Flaws

'39.54 Million Accounts Leaked': Tving Ignored Known Security Flaws

Online video streaming service (OTT) Tving will issue a formal apology on the 3rd, more than three months after a personal information leak incident occurred. On this day, Tving will hold an official press conference and explanation session regarding the cyber intrusion incident, announcing plans to strengthen information security and compensate affected customers. The photo shows Tving's office located in Mapo-gu, Seoul, on September 3, 2026.
Online video streaming service (OTT) Tving will issue a formal apology on the 3rd, more than three months after a personal information leak incident occurred. On this day, Tving will hold an official press conference and explanation session regarding the cyber intrusion incident, announcing plans to strengthen information security and compensate affected customers. The photo shows Tving's office located in Mapo-gu, Seoul, on September 3, 2026.

The Ministry of Science and ICT announced that its investigation into Tving’s data breach incident, which occurred at the end of May this year, revealed that the company identified security vulnerabilities during a 2024 simulation exercise but failed to prepare for hacking attempts. The authorities concluded that the incident resulted from poor key management within Tving, lack of systems to respond to abnormal activities, and inadequate information protection frameworks. It was also pointed out that Tving knew about the personal information breach but did not report it to the authorities in a timely manner.

On the afternoon of the 3rd, the Ministry of Science and ICT released the investigation results regarding the Tving intrusion incident at Sejong University in Seoul, following the government’s analysis of the case. The government highlighted several key issues: △insufficient key management systems, △lack of detection, response, and monitoring systems for abnormal activities, △inadequate information protection governance (structure), △deficiencies in information protection activities, and △delayed reporting of the intrusion incident.

According to the findings, Tving discovered a vulnerability during a 2024 simulated hacking exercise where 'development and operation environment access keys' were exposed without hiding them inside the source code (hardcoded), yet failed to address this issue. Due to selective storage and management practices, system log management policies were not properly applied to new equipment (VPN), resulting in only about six days of connection records being retained. The investigation also revealed that regular security checks, including installation and version management of antivirus software for work PCs, were insufficient.

The investigation team determined that if Tving had properly maintained its key management system, hackers would have been blocked from accessing the development environment and could not have reached the operation environment. It was further revealed that vulnerabilities in source code discovered in 2024, along with access keys stored in plain text without encryption and indiscriminately shared with others via internal messaging platforms, contributed to the breach. The team noted that while access rights should be granted only on a need-to-know basis, all developers were given full access to entire development projects.

Additionally, Tving was found unable to detect or respond to hackers' abnormal attack activities. The company relied solely on basic monitoring such as CPU load, lacking an information protection system capable of real-time detection and blocking of network and data flow anomalies, which exacerbated the damage. Among 265 total employees, including 149 development staff, only about four were dedicated to information security, making it difficult to carry out adequate information protection activities.

Furthermore, despite regulations under the Information and Communications Network Act requiring reporting of intrusion incidents within 24 hours of awareness, Tving reported the incident to KISA (Korea Internet & Security Agency) more than 24 hours after recognizing the situation. As a result, the Ministry of Science and ICT plans to impose an administrative fine of up to 30 million won on Tving.

Meanwhile, Tving identified the information breach while analyzing system overload caused by excessive workload on its database (DB) server at the end of May last year and subsequently reported it to the authorities. The Ministry of Science and ICT and KISA launched an on-site investigation on June 2, forming a joint public-private investigation team that conducted a three-month inquiry into the incident. The findings revealed that a total of 39.54 million accounts were leaked, including 22.06 million active login-enabled accounts, 17.37 million inactive accounts, and 110,000 test accounts, with some overlaps counted multiple times.

"Please note that this article has been automatically translated by AI, and minor discrepancies from the original text may occur due to machine translation limits."