AI Automated Translation.

Font Size

Share

Coupang hit with a 624.7 billion won fine… but what about the '39.54 million accounts' data breach at TVING? Could it be over 10 billion won?

Coupang hit with a 624.7 billion won fine… but what about the '39.54 million accounts' data breach at TVING? Could it be over 10 billion won?

TVING: Core technical assets leaked alongside 20 items across 70 categoriesLast year's revenue: 405.9 billion won… a flat 3% application yields 12.18 billion wonWhile penalty amounts are often tied to company revenue rather than damage scale, this raises fairness concerns

[Seoul=NEWSIS] Reporter Choi Dong-jun = TVING CEO Choi Ju-hee issued an official apology on the 3rd at the Korea Hotel in Jung-gu, Seoul, regarding the personal information breach. September 3, 2026. photocdj@newsis.com /Photo=Choi Dong-jun
[Seoul=NEWSIS] Reporter Choi Dong-jun = TVING CEO Choi Ju-hee issued an official apology on the 3rd at the Korea Hotel in Jung-gu, Seoul, regarding the personal information breach. September 3, 2026. [email protected] /Photo=Choi Dong-jun

As it emerged that personal information from 39.54 million accounts—including duplicates—was leaked from OTT service TVING, attention has turned to the level of penalties imposed by the Personal Information Protection Commission. While Coupang received a fine of 624.681 billion won for data breaches and other violations, TVING, with annual revenue in the low 400 billion won range, may face penalties capped at around 10 billion won under current law. Some critics argue that the structure, which results in smaller fines for companies with lower revenues, inevitably sparks fairness controversies.

According to an IT industry report on the 5th, of Coupang's total fine, 423.575 billion won was for data breaches and safety measure violations, while the remaining 201.16 billion won stemmed from a separate violation involving the unauthorized collection of usage behavior data from 11.17 million users on third-party websites and apps. Even considering only the breach-related amount, TVING's calculated fine at 3% of its revenue—12.18 billion won—is 35 times smaller than Coupang's breach penalty alone.

According to investigation results released by the Ministry of Science and ICT on the 3rd, the leaked TVING accounts include 22.06 million active accounts, 17.37 million dormant or deleted accounts, and 110,000 test accounts. The leaked data items comprise 20 categories across 70 types, including user IDs, passwords, names, birthdates, mobile phone numbers, emails, and linked information (CI). Both mobile phone numbers and emails were leaked along with their encryption keys, leading the government to treat them as effectively plaintext breaches. Additionally, source code for 361 development projects containing authentication, payment, and search algorithms—totaling 30.35 GB—was also exfiltrated. This represents a technical asset breach not seen in Coupang's case.

Inadequate security management was also exposed. Access keys were either exposed within source code or stored in plaintext, and despite identifying this risk during a simulated hacking exercise in 2024, TVING failed to address it. When the data was first exfiltrated, CPU usage on the database server spiked to 100%, yet TVING dismissed the incident as a load issue rather than a breach. It took 14 hours for the information security team to become aware of the incident.

Coupang's final breach scale involved approximately 37.5 million individuals, combining 33.22 million members and 4.33 million non-members. SK Telecom had 23.24 million won subscribers affected by a leak of 25 types of data including SIM authentication keys, resulting in a fine of 134.791 billion won.

The social response burden also differed significantly. For Coupang, the National Assembly held five formal inquiries and hearings; then-CEO Park Dae-jun resigned; and a cross-government task force involving over 10 ministries launched an investigation. SK Telecom faced a new business suspension order, full exemption from penalty fees, and three rounds of National Assembly inquiries. In contrast, TVING's breach was overshadowed by the local election cycle in early June, with its scale only revealed three months later.

Under current Personal Information Protection Act regulations, the maximum administrative fine is capped at 3% of a company's total annual revenue. Applying this to TVING's 2025 revenue of 405.98138 billion won yields a potential fine of 12.17944 billion won. The revised law, set to take effect on the 11th, allows penalties up to 10% of revenue if intentional or grossly negligent breaches affect over 10 million individuals; however, since TVING's breach concluded on May 31, the existing 3% framework applies in principle.

Revenue-linked penalty systems are used by South Korea and the EU (2–4% of revenue) as well as China (5% of prior-year revenue). Japan imposes a fixed maximum fine of up to 100 million yen (approximately 1 billion won). In South Korea, marriage information agency Duo previously faced criticism for receiving only an 1.197 billion won fine despite leaking personal data on over 427,464 individuals across 24 categories including blood type, religion, and educational background—a case widely described as a "cotton cannon" penalty.

An industry insider stated, "Under the current system, the equation 'personal information value = corporate revenue' holds true." They added, "Penalties should be fairer, reflecting aggravating factors such as the number of affected individuals, sensitivity of leaked data, known vulnerabilities that were ignored, and delays in reporting, to ensure penalties align with both the scale and qualitative severity of breaches."

"Please note that this article has been automatically translated by AI, and minor discrepancies from the original text may occur due to machine translation limits."