SEOUL, August 10 (AJP) -South Korea’s widening data-security problem has spread from banks, telecom operators and major online platforms to creator-led media, with the operator of popular financial channel 3PRO TV disclosing that roughly 460,000 pieces of personal information were exposed through its mobile application.
E-Broadcasting Co., which operates 3PRO TV, said it detected signs in early August that an outside actor had gained unauthorized access to other users’ personal information and immediately began an investigation.
The investigation confirmed that an external actor had illegally accessed the 3PRO TV application and maliciously viewed user information, the company said in a notice posted on its website.
The company currently estimates the scale of the exposed data at about 460,000 records. It individually notified members for whom it had contact information and issued the public notice for users it could not reach directly.
Subscribers to 3PRO TV’s YouTube channel were not affected, the company stressed. The breach involved users of 3PRO TV’s own application rather than subscriber information held by YouTube.
The incident adds an influential digital-media operator to the growing range of South Korean businesses facing data-security failures, highlighting how companies that began as content providers increasingly face the same cybersecurity risks as financial institutions and major online platforms once they build their own membership, payment and customer-data systems.
The information exposed differed by user and included names, profile information, mobile phone numbers, email addresses, addresses, bank account information, service-generated records, device information, credit-card information and service-use histories.
More sensitive information was exposed for a relatively small portion of the affected data.
The company said 2,972 bank-account records were exposed, including bank names, account numbers and account-holder names. Information involving 317 credit cards and two addresses was also affected.
The credit-card information consisted of card company names and partially masked card numbers. E-Broadcasting said eight of the 16 digits of the affected card numbers remained masked and that passwords and CVC security codes were not exposed.
The company said the disclosed card information by itself could not be used for unauthorized payments or other direct misuse.
Resident registration numbers and other unique identification or sensitive information were not affected because the company does not collect such data, according to E-Broadcasting.
The breach underscores how South Korea’s data-security problem is extending beyond industries traditionally associated with large repositories of personal information.
Banks and other financial companies have long been prime targets because of the financial and identity information they hold, while telecom companies and large e-commerce and internet platforms have faced heightened scrutiny as their customer databases have grown.
Digital-media businesses are increasingly entering the same territory.
A media outlet that once primarily distributed videos through an external platform can accumulate substantial amounts of personal and financial information after launching its own applications, subscriptions, memberships, payments and other direct-to-consumer services
That transition has transformed companies such as 3PRO TV from content producers into custodians of customer data as well.
3PRO TV began as an economics podcast in 2018 before launching its first YouTube live broadcast in January 2019. It has since grown into one of South Korea’s most prominent online financial-media brands, offering lengthy daily programming covering the U.S. and Korean stock markets, macroeconomic trends, companies and investment issues.
The channel built much of its following by departing from the short, standardized commentary typical of conventional financial television and giving economists, fund managers and market specialists more time to explain the background behind financial and economic developments.
It has since expanded beyond YouTube through its own application and other digital services, turning a creator-driven channel into a broader financial-content platform.
E-Broadcasting said it blocked the suspected attacker’s access route and IP address immediately after identifying the incident and strengthened additional security settings.
The company has also commissioned an external cybersecurity firm to inspect its systems and reported the breach to the Personal Information Protection Commission and the Korea Internet & Security Agency, or KISA.
The combination of names, phone numbers, email addresses and, in some cases, banking information could potentially be used to make phishing messages or impersonation attempts appear more convincing even where the leaked information is insufficient to directly access financial accounts.
E-Broadcasting urged members to be particularly cautious of calls or text messages impersonating 3PRO TV and advised them not to open links or attachments contained in suspicious messages, emails or other communications.
The company said it is preparing customer-support and damage-relief measures and will announce details by Aug. 31 at the latest.
AJP Takeaways
- South Korea’s data-breach problem has reached creator-led media, with about 460,000 personal-information records exposed through the 3PRO TV app.
- Financial data were included in the breach, with 2,972 bank-account records and information involving 317 partially masked credit cards exposed.
- 3PRO TV’s YouTube subscribers were not affected. The breach occurred through E-Broadcasting’s proprietary app, underscoring the cybersecurity responsibilities facing media companies as they expand into memberships, payments and digital platforms.
Copyright ⓒ Aju Press All rights reserved.

