
Personal data from 39.54 million user accounts, including duplicates, was exposed in the hacking of streaming service Tving in late May, an investigation found. Accounts created through simple sign-ups on social networking services accounted for 22.47 million, or about 57% of the total. The attacker exploited weaknesses in Tving's security systems to seize access keys held by a developer and penetrate the company's internal systems, according to the investigation.
The Ministry of Science and ICT released the findings of a joint public-private investigation team into the Tving breach on the 3rd.
The scale of the exposure exceeded expectations because users could register through multiple channels. According to the investigation team, user data was exposed for 39.54 million accounts, including duplicates. Of these, accounts created through simple sign-ups on social networking services — including NAVER, Kakao, Facebook, Apple and X — numbered 22.47 million, the largest share. CJ ONE integrated memberships accounted for 8.63 million and direct Tving sign-ups for 7.26 million. In one case, a single user held as many as 13 accounts.
Of all exposed accounts, 22.06 million were active accounts capable of logging in. Inactive accounts numbered 17.37 million — 8.5 million dormant accounts and 8.87 million withdrawn accounts — along with 110,000 test accounts.
The exposed information covered 20 categories comprising 70 data types, including IDs and passwords, CJ ONE integrated IDs, names, mobile phone numbers, email addresses, birth dates and connecting information (CI). Passwords were one-way encrypted and could not be decrypted into plain text, and refund account numbers were also exposed in encrypted form. However, some mobile phone numbers and email addresses, though encrypted, could be decrypted because the encryption keys were exposed alongside them, the investigation found. The precise scale of the personal data exposure will be determined after further analysis by the Personal Information Protection Commission.
The hacker stole access keys held by a Tving developer, penetrated internal systems and then extracted development projects containing source code along with large volumes of user data. The 361 Tving development projects that were exposed amounted to 30.35 gigabytes of data. These included core technology assets used to run Tving's service, such as personalized content recommendation and search algorithms, user management and authentication systems, payment management and paid service operations.
The attack began with the theft of a developer's access key. Using a development environment access key, the attacker obtained 361 Tving development projects and then located production environment access keys inside them. The development projects contained a total of 43 production environment access keys.
The hacker was able to penetrate Tving's production environment because of lax security management at the company, according to the analysis. The investigation team said Tving did not store production environment access keys separately in a dedicated storage space, instead leaving them plainly exposed within source code for the convenience of developers. The company had even identified the problem during a penetration test in 2024 but did not fix it. Tving employed about four dedicated information security staff, excluding outsourced personnel, compared with 149 developers.
The ministry said no cases of user harm have been confirmed to date and that no signs of illegal trading or distribution through channels such as the dark web have been detected. Still, it said the possibility of secondary harm such as smishing and voice phishing remains, given that mobile phone numbers and email addresses were exposed.
As preventive measures, the ministry directed Tving to build a system for managing the issuance, use, modification and disposal of access keys along with access privileges, and to strengthen detection and monitoring of abnormal activity and bulk data queries. It also instructed the company to secure sufficient information security staff and budget, overhaul its log storage and management policies, and step up remediation of vulnerabilities found through penetration testing and similar reviews.






