Korean Government Reports Data Breach of 39.54 Million Tving Accounts

by Na Seon Hye Posted : September 3, 2026, 14:04Updated : September 3, 2026, 14:04

Personal data from a total of 39.54 million accounts, including active, dormant, and deleted accounts, has been confirmed to have been leaked from the online video service Tving. The actual number of victims is expected to be significantly lower due to many individuals holding multiple accounts, with some having as many as 13.


On September 3, the Ministry of Science and ICT announced the findings of a joint public-private investigation into the Tving data breach that occurred in May. The investigation revealed that approximately 39.54 million accounts were compromised, including 22,063,021 active accounts, 8,502,679 dormant accounts that had not been accessed for over a year, 8,868,174 deleted accounts, and 106,823 test accounts.


Many individuals were found to hold multiple accounts. Tving's structure allows users to create several accounts through social media logins, with some users having as many as 13 accounts.


By account type, there were 7.26 million accounts registered directly with Tving, 8.63 million CJ ONE integrated member accounts, and 22.47 million accounts created through social media logins.


The investigation team identified that a total of 20 items were leaked, including user IDs, passwords, CJ ONE integrated IDs, names, mobile phone numbers, email addresses, birth dates, and resident registration numbers, as well as linked information (CI) that can identify individuals.


While some mobile phone numbers and email addresses were leaked in an encrypted state, the encryption keys were also compromised, allowing for decryption. Therefore, the investigation team assessed this information as being equivalent to plaintext. Passwords were confirmed to have been leaked in a one-way encrypted state, making them impossible to decrypt.


The scope of leaked personal information varied by account characteristics. Of the 19.04 million accounts with CI, 13.24 million remained after removing duplicates. On average, 11.1 items of personal information were leaked from these accounts. In contrast, 20.4 million accounts without CI had an average of 4.6 items leaked.


As a result, the actual number of victims is expected to be lower than the total number of leaked accounts. Excluding test accounts and removing duplicates from CI-holding accounts, the total is 33.64 million. However, it remains difficult to ascertain whether individuals with non-CI accounts held multiple accounts, so the exact number of actual victims has not yet been determined. The investigation team stated that the Personal Information Protection Commission will conduct a detailed analysis of the breach scale and announce specific figures in the future.


Investigation Reveals Attackers Stole Development Environment Access Keys, Leaking 30.35GB of Data


The investigation team also disclosed the scale of the breach, the attackers' infiltration methods, and how personal data was stolen. It was confirmed that the attackers stole the 'development environment access keys' from Tving developers, allowing them to penetrate both the internal development and operational environments.


The attackers extracted development projects in two separate attacks. In the first attack, 14 projects were compromised, while in the second attack, 361 projects accessible through the development environment were leaked. The total size of the leaked projects was 30.35GB, which included source code related to user-customized content recommendations, search algorithms, user management, authentication systems, and payment and paid service operations.


Among these, the source code of 43 projects contained 'operational environment access keys' that could penetrate Tving's operational environment. User information stored in the database (DB) was also found to be saved in plaintext without encryption.


Using this information, the attackers accessed the DB on May 30 and attempted to leak personal data. At that time, the CPU usage of the DB server surged to 100%, triggering an alert, and Tving blocked the related operations.


The following day, the attackers created an internal virtual server using a separate operational environment access key and launched another attack. They transferred 24GB of user information stored in the DB to the virtual server and then exfiltrated it to an external server, deleting the virtual server to cover their tracks. No alerts were triggered during the second attack due to increased server workload.


Tving's Overall Security Lapses Revealed, with Only Four Dedicated Security Personnel


The investigation team concluded that Tving's overall information security system was inadequate, exacerbating the damage. It was confirmed that access keys were exposed directly in the source code or stored in plaintext and shared via internal messaging. All developers were granted access to all development projects, meaning that compromising a single access key allowed access to the entire project. There was also a lack of a real-time detection and response system for abnormal signs, such as CPU load.


Tving had discovered a 'hardcoding' vulnerability in access keys during a simulated hacking exercise in 2024 but failed to make improvements. The number of dedicated security personnel was only four, which is insufficient compared to 149 development staff and a total of 265 employees. Records of access to new virtual private network (VPN) equipment were only kept for about six days, and regular security checks, such as antivirus management for work PCs, were inadequate. After recognizing the breach, Tving reported it to the Korea Internet & Security Agency (KISA) about 29 hours later, violating the Information and Communications Network Act, which mandates reporting within 24 hours.


The Ministry of Science and ICT has instructed Tving to submit a plan for implementing measures to prevent recurrence based on the investigation results by the end of this month. Tving will implement these measures from October to December, and the ministry will begin monitoring compliance in January. If any deficiencies are found, corrective actions will be mandated under the Information and Communications Network Act.


Meanwhile, Tving is expected to announce its official stance along with plans for enhancing information security and customer compensation measures.





* This article has been translated by AI.