A joint investigation released on Thursday has revealed that nearly 40 million user accounts on South Korean streaming platform Tving were compromised in a large-scale data leak stemming from a hacking incident reported in June. The Ministry of Science and ICT has disclosed the findings of a three-month collaborative government and private-sector probe into the Tving data breach. Tving is an online video streaming service operated by entertainment conglomerate CJ ENM.
According to the ministry, the breach occurred on June 1, with a total of 39.54 million user accounts and 361 technical assets, including source code, being stolen. However, the account count includes multiple accounts registered under the same username. The report noted that Tving has since strengthened its security measures, and no signs of further attacks have been detected to date.
By registration method, the compromised accounts included 7.26 million directly registered with Tving, 8.63 million unified membership accounts under CJ ONE, and 22.47 million accounts created through social login services such as Naver, Kakao, Facebook, Apple, and X platform. Among all affected accounts, 22.06 million were active accounts with normal login capability, while 17.37 million were inactive, comprising dormant accounts and those that had been deregistered.
The leaked information spans 70 data items across 20 major categories, including names, birth dates, mobile phone numbers, email addresses, and linked information. However, the type and extent of the leaked data vary depending on how users registered their accounts. The Personal Information Protection Commission will separately confirm the actual scale of this personal information leak and determine the penalty amount.
Investigators determined that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems. The investigation also found that after detecting the security incident on May 30, Tving failed to report it to the Korea Internet & Security Agency within 24 hours, only completing the notification on June 1. This delayed reporting could result in fines.
Investigators have warned of the risk of secondary harm, stating that hackers may exploit the stolen data for further attacks, and the leaked personal information could also be used in cybercrimes such as SMS phishing and voice phishing scams. This data breach represents a significant blow to Tving, which had just begun improving its business performance. Tving posted second-quarter revenue of 140.7 billion won (approximately $103.6 million), with an operating profit of 6 billion won. This marked the platform's first quarterly profit since it was spun off as an independent entity in 2020.