Tving Data Breach Exposes 39.54 Million Accounts

By Na Seon Hye Posted : September 3, 2026, 16:00 Updated : September 3, 2026, 16:00

Approximately 39.54 million user accounts, including active, dormant, and canceled accounts, have been confirmed as compromised in a data breach involving the online video service Tving. The actual number of affected individuals remains undetermined, as one person may hold up to 13 accounts. There is no evidence that social media accounts from platforms like Naver or Kakao were breached.


On September 3, the Ministry of Science and ICT announced the results of a joint public-private investigation into the Tving data breach that occurred in May. An official from the investigation team stated, "About 39.54 million accounts, including duplicates, were leaked."


According to the investigation, the leaked accounts include 22,063,021 active accounts, 8,502,679 dormant accounts that had not been accessed for over a year, 8,868,174 accounts that were deactivated due to membership cancellation, and 106,823 test accounts, totaling 39,546,697 accounts.


The investigation concluded that there was no risk of external SNS data being leaked or accessed. An official noted, "The information that was transferred to Tving during the SNS quick sign-up process, such as names, email addresses, some birth years, and genders, was leaked, but not the personal data from external SNS accounts."


However, mobile phone numbers and linked information (CI) collected during the identity verification process were included in the data breach.


The investigation team indicated that Tving did not initially verify the duplication of sign-up routes during its growth, allowing individuals to register multiple times through various channels, including direct sign-ups and through CJ ONE, Naver, and Kakao. It was found that one individual could hold up to 13 accounts based on CI verification.


The scope of leaked personal information varied by account type. The investigation identified a total of 20 items that were leaked, including user IDs, passwords, CJ ONE integrated IDs, names, mobile phone numbers, email addresses, birth dates, and linked information (CI) that identifies individuals.


Notably, accounts with CI had a different extent of leaked information. There were 19,040,000 accounts with CI, and after removing 5,800,000 duplicate accounts based on the same CI, 13,240,000 accounts remained. On average, 11.1 items were leaked from these accounts. In contrast, 20,400,000 accounts without CI had an average of 4.6 items leaked.


The investigation team confirmed the exact number of duplicate accounts among CI-holding accounts but could not ascertain the precise scale of duplication among the 20,400,000 accounts without CI, as they could potentially be linked to CI-holding accounts or duplicate among themselves. The actual number of affected individuals after removing duplicates will be determined following further investigation by the Personal Information Protection Commission.


Accounts without CI did not undergo identity verification, leading to many instances of missing or inaccurate information. The investigation team stated, "Since CI is not information that users directly input or use for login, the risk of it being misused alone is low. However, when combined with other personal information like names and mobile phone numbers, it could be used for smishing or phishing attacks." They added that the Korea Communications Commission is developing protective measures in response to the CI leak.


The investigation team also looked into the initial infiltration route of the attackers but could not determine the exact cause. An official stated, "We examined various scenarios, including phishing, malware infection, supply chain attacks, and misuse of access keys, and conducted forensic analysis on related PCs and laptops. However, we could not find evidence to support these scenarios, and the route of the initial development environment access key theft remains unclear." The police are currently investigating the attackers and the specific route of the access key theft.


The investigation team concluded that Tving's internal security response capabilities were inadequate, contributing to the extent of the damage. Tving has only four dedicated information security personnel, which is insufficient compared to its 149 development staff and a total of 265 employees. An official from the investigation team remarked, "With only four dedicated personnel, there are limits to the various information security activities that can be performed. If Tving presents a plan for increasing personnel, we will discuss the adequacy of the number and budget compared to similar companies."





* This article has been translated by AI.

Copyright ⓒ Aju Press All rights reserved.