A breach at 'TVING', one of South Korea's leading over-the-top (OTT) streaming platforms, exposed all 39.54 million user accounts as well as core technology assets in an unprecedented incident. The breach resulted from human error: access keys were left unencrypted and unattended, and the company's delayed response means it faces a fine of up to 30 million won. The Ministry of Science and ICT formally announced the findings of its investigation with a public-private joint investigation team at the Government Complex-Seoul on Sept. 3.

All accounts exposed, from dormant to test accounts, in disaster tantamount to plaintext leak
According to the investigation team, information from a total of 39.54 million accounts was stolen in the breach: 22.06 million active accounts that could be used to log in, 17.37 million inactive accounts that were dormant or closed, and 110,000 test accounts. Lim Jeong-gyu, director general for information security and network policy at the Ministry of Science and ICT, acknowledged the severity of the incident at a briefing, saying, "In effect, every account held by TVING was exposed."
The leaked data covered 20 categories, or 70 types of information, including user IDs and passwords, names, dates of birth, mobile phone numbers, email addresses and connected information (CI). The passwords were protected with one-way encryption and cannot be decrypted. But the complete theft of the encryption keys for mobile phone numbers and email addresses left them effectively exposed in plaintext, causing severe damage. The attackers also stole 361 development projects, totaling 30.35 gigabytes, containing core technology assets such as TVING's personalized content recommendation algorithm and payment management system.

Hard-coded keys hidden in source code made security collapse inevitable
The attacker used a developer's previously stolen 'development-environment access key' to extract projects from May 29 through May 31. The bigger problem was the subsequent discovery of 43 'production-environment access keys' stored unprotected inside the source code, which enabled the attacker to penetrate the Amazon Web Services (AWS)-based production environment as well.
The investigation found that TVING's 'security management system' was comprehensively deficient. The company failed to separate its production-environment access keys and instead left them exposed directly in the source code through so-called 'hard-coding.' Database (DB) access information was also left lying around in plaintext. Particularly damaging was the company's complacency in taking no corrective action after identifying the vulnerability during an internal simulated-hacking exercise in 2024.
![TVING [Provided by TVING. Resale and redistribution prohibited]](https://cdn.www.cineplay.co.kr/w900/q75/article-images/2026-09-03/f64addb1-de77-46ed-9f35-0156d6d7ab2d.jpg)
Delayed response missed legal deadline as government sanctions and police probe accelerate
The identity of the initial attacker remains unknown, while police pursue an intensive investigation after finding indications that the stolen information was transferred to accounts overseas.
TVING's response after the breach also came under scrutiny. The Act on Promotion of Information and Communications Network Utilization requires companies to report a breach to the relevant authorities within 24 hours of becoming aware of it, but TVING filed its report late. The Ministry of Science and ICT therefore plans to impose a fine of up to 30 million won under the relevant laws.
The government required TVING to establish measures to prevent a recurrence, including rigorous key management and access-control systems and a substantial expansion of dedicated information-security staff. It plans to begin intensive compliance inspections in January next year.
#TVING #TVING #DataBreach #DataBreach #LimJungGyu #LimJungGyu #MSIT #MSIT #Hardcoding #Hardcoding #Cybersecurity

댓글 (0)
댓글 작성
댓글을 작성하려면 로그인이 필요합니다.
로그인하기