
A hacking attack on Tving in late May exposed personal information from 39.54 million user accounts, including multiple accounts held by the same individual, an investigation found. The attacker exploited weak security systems to steal an access key and penetrate Tving's internal systems, according to the findings. Tving issued a public apology and announced an information security investment plan along with a customer compensation package.
The Ministry of Science and ICT released the results of a joint public-private investigation team's probe into the Tving breach at the Seoul Government Complex on the 3rd. Lim Jung-kyu, director general for information security and network policy at the ministry, said at a briefing that all Tving accounts had been exposed, including active, inactive and test accounts.
Counting duplicates, the total number of exposed accounts reached 39.54 million. Accounts created through social media sign-ups, including NAVER and Kakao, numbered 22.47 million, or about 57%. CJ ONE integrated memberships followed at 8.63 million, and accounts registered directly with Tving totaled 7.26 million. Of these, 22.06 million were active accounts capable of logging in. Inactive accounts numbered 17.37 million, consisting of 8.5 million dormant accounts and 8.87 million withdrawn accounts, while test accounts totaled 110,000. Investigators found one case in which a single user held as many as 13 accounts.

The exposed data spanned 20 categories, covering 70 types of information, including IDs and passwords, names, mobile phone numbers, email addresses, dates of birth and connecting information (CI). The investigation team confirmed that the data was transferred to overseas accounts rather than domestic ones, but the exact country and server locations remain under police investigation. No secondary damage to users, such as illegal dark web transactions, has been confirmed so far.
The attack took place over three days from May 29 to 31. After stealing a development environment access key to penetrate Tving's internal systems, the attacker located production environment access keys across 361 development projects. Using those keys, the attacker breached the cloud storage holding the user database and extracted user information.
Tving's failure to block the attack stemmed largely from lax security practices. Access keys were not stored separately in a dedicated repository but were left exposed in plain text within source code for the convenience of developers. The company had identified the problem during a penetration test in 2024 but did not fix it.
Tving held a briefing at the Koreana Hotel in Seoul's Jung District that day, announcing plans to quadruple its information security investment by 2030 and establish an information security innovation advisory committee. The company also said it would provide affected customers with identity protection insurance and Tving points worth 5,000 won. Choi Joo-hee, chief executive of Tving, bowed in apology and said the company humbly accepts the final findings of the joint public-private investigation team and will carry out all necessary corrective measures and preventive steps for the issues raised, with a sense of responsibility, to the end. She added that the company will treat information protection as its most important responsibility and a source of competitiveness, and will rebuild its entire security framework from the ground up by expanding security investment and staffing.






