
It has been revealed that personal information from a total of 39.54 million accounts was leaked due to the TVING security breach that occurred in May this year. All of TVING's subscriber data was compromised, and personal information from 527,000 accounts registered to use free TVING vouchers provided through KT's customer appreciation program was also leaked.
The Ministry of Science and ICT announced the results of a joint government-industry investigation into the TVING security breach on the afternoon of the 3rd at its office in Sejong University, Seoul.
According to the investigation, a total of 39.54 million accounts (including duplicates) were leaked: 22.06 million active accounts, 17.37 million inactive accounts (8.5 million dormant and 8.87 million cancelled), and 110,000 test accounts. Additionally, 361 projects (totaling 30.35 GB) that were under development at TVING were also leaked.
The scale of damage from this security breach was significant, primarily due to a relatively easy registration structure. TVING allowed users to hold up to 13 accounts per individual, resulting in numerous duplicate accounts. In addition to CJ ONE (Won), users could easily register through various social media platforms including Naver, Kakao, X (formerly Twitter), Apple, and Facebook.
In fact, accounts registered directly with TVING numbered 7.26 million, accounting for only 18% of the leaked accounts. The majority of the remaining leaked accounts were generated through CJ Won integrated membership (8.63 million) and SNS quick registration (22.47 million).
The information leaked in this security breach included 20 items (70 types): ID, password (one-way encrypted), CJ Won integrated ID, name, phone number, email, date of birth, and linkage information for personal identification (CI).
CI is a unique online identifier for individuals; when combined with other information, it can enable specific identification of individuals and may be exploited for smishing, phishing, and other attacks. There were 19.04 million accounts holding CI data (13.24 million after removing duplicates). The leaked information for these accounts averaged 11.1 items per account, compared to only 4.6 items for accounts without CI. Among the accounts with CI, 9.49 million were active (excluding 3.7 million dormant and 50,000 cancelled accounts).
SNS quick login accounts provided only email and name to TVING, while accounts registered through Naver additionally provided year of birth and gender. Im Jeong-gyu, Policy Officer for Information Protection Networks, explained that "there is no risk of simultaneous leakage of SNS account information even if TVING data was compromised." No signs of secondary victimization of users or illegal transactions on the dark web have been detected so far.
It was revealed that attackers stole personal information using access keys. First, they stole 'development environment access keys' to leak all 361 projects currently under development at TVING. They then used 'operational environment access keys' found within the source code of these projects to access the operational environment and extract personal information. Police are currently investigating to identify the attackers in this incident.
TVING initially stated that it became aware of the security breach at 3:09 p.m. on May 31. However, the investigation team determined that the suspected data leak was communicated to the information security team at 10:10 a.m. on the same day. The reporting time to the Korea Internet & Security Agency (KISA) was 3:08 p.m. on June 1. Although there was no intent, more than 24 hours had passed since awareness, so the Ministry of Science and ICT plans to impose an administrative fine of up to 30 million won on TVING under the Information and Communications Network Act. Since this incident occurred on May 30, it does not fall under the scope of the strengthened Information and Communications Network Act (effective October 1) or the Personal Information Protection Act (effective September 11).
The Ministry of Science and ICT cited several issues with TVING: inadequate access key management systems, lack of abnormal access monitoring systems, insufficient information governance (only 4 out of 256 total staff were in information security), and delayed reporting of the security breach. Accordingly, TVING is required to submit an implementation plan for preventive measures by September, and its compliance will be reviewed three months later in January next year.