Tving Data Breach Hits 39.54 Million Accounts, Vows Fourfold Security Spending

Poor Management of Development Environment Access Keys Exposed 20 Data Categories, Including Names and Contact Details Social Media Sign-Ups Accounted for 57% of Affected Accounts Company Offers Insurance and Points as Customer Compensation

Technology|
|
By Kim Ki-hyuk and Roh Hyun-seobcoldmetal@sedaily.com, hit8129@sedaily.com
||
Tving CEO Choi Joo-hee (second from right) bows in apology alongside executives over the personal data breach at the Koreana Hotel in Seoul's Jung district on Feb. 3. Yonhap News - Seoul Economic Daily Technology News from South Korea
Tving CEO Choi Joo-hee (second from right) bows in apology alongside executives over the personal data breach at the Koreana Hotel in Seoul's Jung district on Feb. 3. Yonhap News

A hacking attack on Tving in late May exposed personal information from 39.54 million user accounts, including multiple accounts held by the same individual, an investigation found. The attacker exploited weak security systems to steal an access key and penetrate Tving's internal systems, according to the findings. Tving issued a public apology and announced an information security investment plan along with a customer compensation package.

The Ministry of Science and ICT released the results of a joint public-private investigation team's probe into the Tving breach at the Seoul Government Complex on the 3rd. Lim Jung-kyu, director general for information security and network policy at the ministry, said at a briefing that all Tving accounts had been exposed, including active, inactive and test accounts.

Counting duplicates, the total number of exposed accounts reached 39.54 million. Accounts created through social media sign-ups, including NAVER and Kakao, numbered 22.47 million, or about 57%. CJ ONE integrated memberships followed at 8.63 million, and accounts registered directly with Tving totaled 7.26 million. Of these, 22.06 million were active accounts capable of logging in. Inactive accounts numbered 17.37 million, consisting of 8.5 million dormant accounts and 8.87 million withdrawn accounts, while test accounts totaled 110,000. Investigators found one case in which a single user held as many as 13 accounts.

Lim Jung-kyu, director general for information protection and network policy at the Ministry of Science and ICT, announces the findings of a joint public-private investigation team's probe into the Tving breach at the Government Complex Seoul on Feb. 3. Yonhap News - Seoul Economic Daily Technology News from South Korea
Lim Jung-kyu, director general for information protection and network policy at the Ministry of Science and ICT, announces the findings of a joint public-private investigation team's probe into the Tving breach at the Government Complex Seoul on Feb. 3. Yonhap News

The exposed data spanned 20 categories, covering 70 types of information, including IDs and passwords, names, mobile phone numbers, email addresses, dates of birth and connecting information (CI). The investigation team confirmed that the data was transferred to overseas accounts rather than domestic ones, but the exact country and server locations remain under police investigation. No secondary damage to users, such as illegal dark web transactions, has been confirmed so far.

The attack took place over three days from May 29 to 31. After stealing a development environment access key to penetrate Tving's internal systems, the attacker located production environment access keys across 361 development projects. Using those keys, the attacker breached the cloud storage holding the user database and extracted user information.

Tving's failure to block the attack stemmed largely from lax security practices. Access keys were not stored separately in a dedicated repository but were left exposed in plain text within source code for the convenience of developers. The company had identified the problem during a penetration test in 2024 but did not fix it.

Tving held a briefing at the Koreana Hotel in Seoul's Jung District that day, announcing plans to quadruple its information security investment by 2030 and establish an information security innovation advisory committee. The company also said it would provide affected customers with identity protection insurance and Tving points worth 5,000 won. Choi Joo-hee, chief executive of Tving, bowed in apology and said the company humbly accepts the final findings of the joint public-private investigation team and will carry out all necessary corrective measures and preventive steps for the issues raised, with a sense of responsibility, to the end. She added that the company will treat information protection as its most important responsibility and a source of competitiveness, and will rebuild its entire security framework from the ground up by expanding security investment and staffing.

Original reporting by Kim Ki-hyuk and Roh Hyun-seob for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
2:05

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.