Find your next favorite work.

'TVING' breach exposes all 39.54 million accounts ... delayed reporting over abandoned access keys brings 30 million won fine

361 core technology assets, including source code, leaked after plaintext access keys were left exposed despite a simulated-hacking warning

A breach at 'TVING', one of South Korea's leading over-the-top (OTT) streaming platforms, exposed all 39.54 million user accounts as well as core technology assets in an unprecedented incident. The breach resulted from human error: access keys were left unencrypted and unattended, and the company's delayed response means it faces a fine of up to 30 million won. The Ministry of Science and ICT formally announced the findings of its investigation with a public-private joint investigation team at the Government Complex-Seoul on Sept. 3.

Why were 39.54 million TVING accounts breached? Poor access-key management was the root cause An investigation confirmed that 361 technology assets, including source code, and approximately 39.54 million user accounts were leaked from TVING, an over-the-top (OTT) streaming platform. The Ministry of Science and ICT announced the findings of a public-private joint investigation into the TVING breach at the Government Complex-Seoul on Sept. 3. Lim Jeong-gyu, director general for information security and network policy at the Ministry of Science and ICT, announces the investigation findings at the Government Complex-Seoul on Sept. 3, 2026.
Why were 39.54 million TVING accounts breached? Poor access-key management was the root cause An investigation confirmed that 361 technology assets, including source code, and approximately 39.54 million user accounts were leaked from TVING, an over-the-top (OTT) streaming platform. The Ministry of Science and ICT announced the findings of a public-private joint investigation into the TVING breach at the Government Complex-Seoul on Sept. 3. Lim Jeong-gyu, director general for information security and network policy at the Ministry of Science and ICT, announces the investigation findings at the Government Complex-Seoul on Sept. 3, 2026.

All accounts exposed, from dormant to test accounts, in disaster tantamount to plaintext leak

According to the investigation team, information from a total of 39.54 million accounts was stolen in the breach: 22.06 million active accounts that could be used to log in, 17.37 million inactive accounts that were dormant or closed, and 110,000 test accounts. Lim Jeong-gyu, director general for information security and network policy at the Ministry of Science and ICT, acknowledged the severity of the incident at a briefing, saying, "In effect, every account held by TVING was exposed."

The leaked data covered 20 categories, or 70 types of information, including user IDs and passwords, names, dates of birth, mobile phone numbers, email addresses and connected information (CI). The passwords were protected with one-way encryption and cannot be decrypted. But the complete theft of the encryption keys for mobile phone numbers and email addresses left them effectively exposed in plaintext, causing severe damage. The attackers also stole 361 development projects, totaling 30.35 gigabytes, containing core technology assets such as TVING's personalized content recommendation algorithm and payment management system.

Why were 39.54 million TVING accounts breached? Poor access-key management was the root cause An investigation confirmed that 361 technology assets, including source code, and approximately 39.54 million user accounts were leaked from TVING, an over-the-top (OTT) streaming platform. The Ministry of Science and ICT announced the findings of a public-private joint investigation into the TVING breach at the Government Complex-Seoul on Sept. 3. Lim Jeong-gyu, director general for information security and network policy at the Ministry of Science and ICT, announces the investigation findings at the Government Complex-Seoul on Sept. 3, 2026.
Why were 39.54 million TVING accounts breached? Poor access-key management was the root cause An investigation confirmed that 361 technology assets, including source code, and approximately 39.54 million user accounts were leaked from TVING, an over-the-top (OTT) streaming platform. The Ministry of Science and ICT announced the findings of a public-private joint investigation into the TVING breach at the Government Complex-Seoul on Sept. 3. Lim Jeong-gyu, director general for information security and network policy at the Ministry of Science and ICT, announces the investigation findings at the Government Complex-Seoul on Sept. 3, 2026.

Hard-coded keys hidden in source code made security collapse inevitable

The attacker used a developer's previously stolen 'development-environment access key' to extract projects from May 29 through May 31. The bigger problem was the subsequent discovery of 43 'production-environment access keys' stored unprotected inside the source code, which enabled the attacker to penetrate the Amazon Web Services (AWS)-based production environment as well.

The investigation found that TVING's 'security management system' was comprehensively deficient. The company failed to separate its production-environment access keys and instead left them exposed directly in the source code through so-called 'hard-coding.' Database (DB) access information was also left lying around in plaintext. Particularly damaging was the company's complacency in taking no corrective action after identifying the vulnerability during an internal simulated-hacking exercise in 2024.

TVING [Provided by TVING. Resale and redistribution prohibited]
TVING [Provided by TVING. Resale and redistribution prohibited]

Delayed response missed legal deadline as government sanctions and police probe accelerate

The identity of the initial attacker remains unknown, while police pursue an intensive investigation after finding indications that the stolen information was transferred to accounts overseas.

TVING's response after the breach also came under scrutiny. The Act on Promotion of Information and Communications Network Utilization requires companies to report a breach to the relevant authorities within 24 hours of becoming aware of it, but TVING filed its report late. The Ministry of Science and ICT therefore plans to impose a fine of up to 30 million won under the relevant laws.

The government required TVING to establish measures to prevent a recurrence, including rigorous key management and access-control systems and a substantial expansion of dedicated information-security staff. It plans to begin intensive compliance inspections in January next year.

#TVING #TVING #DataBreach #DataBreach #LimJungGyu #LimJungGyu #MSIT #MSIT #Hardcoding #Hardcoding #Cybersecurity

×

Related keywords

댓글 (0)

아직 댓글이 없습니다. 첫 댓글을 작성해보세요!

댓글 작성