
CJ ENM's OTT (online video service) Tving has officially apologized for the cyber intrusion incident. Tving announced it will provide one year of hacking and phishing peace-of-mind insurance to customers and pay 5,000 won in Tving points. Additionally, by 2030, information security investment will be increased to approximately four times the level of the previous five years, and the number of security professionals will be expanded to three times the current level.
On the 3rd, Tving held a press conference on the cyber intrusion incident at the Korea Hotel in Gwanghwamun, Seoul, presenting customer compensation measures and mid-to-long-term information security strengthening plans.
Tving CEO Choi Ju-hee bowed her head, saying, "We humbly accept the findings of the joint government-industry investigation," and "We sincerely apologize to all customers for the worry and anxiety caused by this intrusion incident."
The customer compensation package consists of hacking and phishing peace-of-mind insurance, an upgrade to a premium viewing environment, Tving points, and entertainment coupons. The peace-of-mind insurance will be provided for one year and covers up to 3 million won per person in cases of cyber financial fraud due to hacking or phishing, online shopping mall fraud, or direct peer-to-peer transaction fraud.
Customers will also receive an upgrade to a premium viewing environment without separate application, along with 5,000 won in Tving points usable for individual purchases of the latest movies and other content. They can also choose either a one-month Wave AVOD subscription (worth 5,500 won) or a CGV combo coupon offering a 5,000 won discount on three types of combos. Applications for the compensation package will be accepted from the 7th to the 30th, with benefits applied starting the 6th of next month.
SK Telecom and KT, which recently experienced cyber intrusion incidents, have also announced customer compensation measures and plans to expand information security investments. Tving has chosen to offer a package combining insurance and content benefits rather than direct fee discounts.
Security investment to prevent recurrence will also be expanded. By 2030, Tving will increase information security investment to approximately four times the level of the previous five years and plans to expand its security professionals to three times the current number over the next five years. The security organization will be further segmented into product, cloud, corporate IT, and compliance security divisions.
The security system will be rebuilt based on the "zero trust" principle, which does not trust users or devices from the start but verifies them every time access is requested. Only the minimum necessary permissions required for a job and purpose will be granted, and system and network areas will be separated. AI-based risk detection and real-time automatic blocking and isolation systems will also be strengthened. A practical security council will be established under the CEO-CISO (Chief Information Security Officer) and CPO (Chief Privacy Officer) framework, and a "Information Security Innovation Advisory Committee" directly reporting to the CEO will also be formed.
Choi (CEO) stated, "We deeply reflect on this incident and will fundamentally rebuild our entire security system from scratch," adding, "We will treat information security as the most important responsibility and competitive advantage of our platform."