Wednesday, September 16, 2026

TVING Neglected Known Security Vulnerabilities, Resulting in the Theft of 39.54 Million Accounts

Input
2026-09-03 15:56:23
Updated
2026-09-03 15:56:23
[Financial News] A government investigation has revealed that approximately 39.54 million user accounts and 361 core technology assets used for recommendation and search algorithms, as well as authentication and payment management, were leaked from the online video service (OTT) TVING.
The government’s assessment is that TVING exacerbated the damage by failing to fix a vulnerability that exposed the “development and production environment access key” directly within the source code, even though the vulnerability was discovered during a penetration test conducted in 2024.
On the 3rd, the Ministry of Science and ICT announced at Government Complex Seoul that the Public-Private Joint Investigation Team had confirmed the leakage of a total of 39.54 million accounts in its investigation into the TVING breach, including 22.06 million active accounts capable of logging in, 17.37 million inactive accounts due to dormancy or withdrawal, and 110,000 test accounts.
However, the investigation team explained that the number of leaked accounts cannot be regarded as the personal information of 39.54 million individuals having been leaked. The figure included duplicate accounts, as a single individual could have up to 13 accounts.
Lim Jeong-gyu, Director General of Information Security and Network Policy at the Ministry of Science and ICT, is announcing the results of the investigation into the TVING breach at Government Complex Seoul in Jongno-gu, Seoul, on the 3rd. It was determined that 361 TVING development projects containing technical asset source code had been leaked. /Photo = News1

Therefore, the specific number of individuals whose personal information was leaked is expected to be confirmed through a separate investigation by the Personal Information Protection Commission (PIPC).
It has only been confirmed that the hacker responsible for the large-scale data leak transferred the information overseas; the perpetrator has not been identified. The government explained that it plans to identify the culprit through a separate investigation.
Core source code and technical assets also leaked... “Information leaked overseas”

As it has been revealed that the recent TVING data breach went beyond the simple leakage of personal information and involved the leakage of core technical assets used for recommendation and search algorithms, as well as authentication and payment management, calls for accountability regarding TVING’s overall security management system are growing.
A total of 39.54 million accounts were leaked. The leaked data included 20 categories and 70 types of information, ranging from IDs and names to dates of birth, mobile phone numbers, email addresses, and linked information (CI). Passwords were also included in the leak, but investigators determined that they could not be decrypted because they were one-way encrypted.
A government investigation has revealed that approximately 39.54 million user accounts and 361 core technical assets used for recommendation and search algorithms, as well as authentication and payment management, were leaked from the online video streaming service (OTT) TVING. The government’s assessment is that TVING caused large-scale damage by failing to fix a vulnerability discovered during a penetration test in 2024, which exposed “development and production environment access keys” directly within the source code. (ChatGPT-generated image) / Photo = News1

The problem lies with mobile phone numbers and email addresses. The government determined that because not only the information itself but also the encryption keys were leaked, the incident was effectively equivalent to the exposure of plaintext.
Concerns about secondary damage from the leakage of CI information

The greatest concern is that the leaked personal information could be combined with other data and used for additional crimes. Since phone numbers, email addresses, and names were leaked together, they could be exploited in targeted attacks such as phishing, smishing, and impersonation messages.
In particular, if a TVING user has used the same or similar ID and password on other services, the damage could escalate through account hijacking.
The investigation team stated, “CI information is not entered directly by users and therefore cannot be used for login; however, because it could be exploited for smishing or phishing when combined with other information, countermeasures are being prepared.”
Another point worth noting is the technical assets leaked along with the personal information. The attackers took approximately 30.35 GB of data from 361 development projects containing source code. Since the data includes code used for user recommendation and search algorithms, as well as authentication and payment management, the incident is considered to be on an entirely different level from a simple customer information breach.
149 developers vs. 4 dedicated information security personnel

The investigation team pointed out that TVING’s internal security management failed to detect that an attacker had infiltrated the system and was carrying out activities, thereby exacerbating the damage.
The hacker first stole a development environment access key held by a developer, infiltrated TVING’s operating environment system, and then accessed the database (DB) to retrieve user information and attempt to exfiltrate it. However, TVING failed to detect and block the abnormal access and large-scale data queries in real time.
Subsequently, on May 30, a system anomaly occurred as the workload on the DB server surged, and unauthorized access was discovered during the ensuing investigation. Furthermore, the investigation team concluded that TVING’s information security management system was inadequate, noting that while the development workforce numbered 149, there were only four dedicated information security personnel.
The incident report was also submitted after the legal deadline. TVING became aware of the breach at 10:10 a.m. on May 31, but reported it to the Korea Internet & Security Agency (KISA) at 3:08 p.m. on June 1.
This exceeded the statutory reporting deadline of 24 hours. The Ministry of Science and ICT plans to impose a fine of up to 30 million won for violating the Information and Communications Network Act.
Personal Information Protection Commission expected to impose a penalty based on its investigation

In addition to the fine imposed by the Ministry of Science and ICT, TVING is expected to face a penalty following an investigation by the Personal Information Protection Commission (PIPC).
The Personal Information Protection Commission received a report from TVING concerning the leakage of personal information last June and launched an on-site investigation.
However, because TVING’s personal information breach occurred last May, it is not subject to the revised Personal Information Protection Act, which imposes punitive fines of up to 10% of total revenue in cases of large-scale personal information leaks.
It also avoided being subject to regulations under the amended Information and Communications Network Act, which strengthens measures such as enforcement fines starting October 1.
Claims for damages by users alleging that their information was leaked are also a variable. As the actual scale of the damage and the extent of the legal violations are determined, TVING’s legal and financial burden could increase.
[email protected] Lee Gu-sun Reporter