TVING to Compensate Up to 3 Million Won Over 'Personal Data Leak'... Quadruples Security Investment
- Input
- 2026-09-03 16:59:31
- Updated
- 2026-09-03 16:59:31

[Financial News] Online video streaming service (OTT) TVING is stepping up customer compensation and security investments to restore user trust damaged by a large-scale personal information leak. The company will provide hacking and phishing protection insurance guaranteeing up to 3 million won and TVING points, and will increase its investment in information security over the next five years fourfold compared to the previous five years. It has decided to completely rebuild its security system after it was revealed that information on 39.54 million accounts, including duplicates, was leaked and measures taken regarding previously discovered security vulnerabilities were insufficient.
At a briefing held at the Koreana Hotel in Gwanghwamun, Seoul, on the 3rd, TVING CEO Julie Choi bowed her head and said, "We humbly accept the results of the joint public-private investigation team and sincerely apologize for causing concern and anxiety to our customers due to this incident," adding, "We will responsibly implement measures to prevent recurrence."
At the event, TVING also unveiled a customer compensation package and mid- to long-term information security innovation plans. The compensation package consists of hacking and phishing protection insurance, a premium viewing environment upgrade, TVING points, and entertainment coupons.
The protection insurance is provided for one year and compensates up to 3 million won per person for cyber financial fraud resulting from hacking and phishing, as well as fraud involving online shopping malls and direct person-to-person transactions. It automatically upgrades users to a premium viewing environment and provides 5,000 won worth of TVING points that can be used to purchase the latest movies. Users can also choose between a one-month Wavve AVOD subscription worth 5,500 won and a 5,000-won discount coupon for one of three CGV combo options. Claims for compensation will be accepted from the 7th to the 30th of this month and will take effect starting on the 6th of next month.
Investment in security will also be significantly expanded. TVING plans to increase its investment in information security by approximately four times by 2030 compared to the previous five years and triple its security workforce over the next five years. The plan is to subdivide the security organization into Product, Cloud, Enterprise IT, and Compliance divisions.
The security system will also be rebuilt based on Zero Trust. Access rights will be granted only within the necessary scope according to job function and purpose, and system and network domains will be separated. AI-based intelligent detection and real-time automated response systems will also be strengthened. An 'Information Security Innovation Advisory Committee' directly under the CEO will be established to undergo verification by external experts.
According to the final investigation results announced earlier today by the Ministry of Science and ICT's public-private joint investigation team, a total of 39.54 million accounts were leaked as a result of this incident, including 22.06 million active accounts, 17.37 million inactive accounts, and 110,000 test accounts. However, duplicate accounts were also included, such as cases where one person held up to 13 accounts. The specific scale of the personal information leak is expected to be confirmed through a separate investigation by the Personal Information Protection Commission (PIPC).
In addition to personal information, 361 development projects containing source code and technical assets totaling 30.35 GB were leaked. It was confirmed that the source code in question is an asset used in the development of the TVING service. The investigation team determined that TVING exacerbated the damage by failing to fix a vulnerability in which access keys for development and operating environments were exposed in the source code, even after discovering it during a 2024 penetration test.
CEO Julie Choi stated, "We deeply reflect on this incident and will rebuild our entire security system from the ground up," adding, "We will make information protection the platform's most important responsibility and competitive advantage, and do our utmost to restore customer trust."
[email protected] Choi Hye-rim, Lee Gu-soon Reporter