TVING's Revenue Up 26-Fold in Five Years, but It Has Just Four Dedicated Privacy Staff ... "Made Matters Worse"
- Input
- 2026-09-23 10:08:07
- Updated
- 2026-09-23 10:08:07

According to data that Lee Hoon-gi, a lawmaker of the Democratic Party of Korea on the National Assembly's Science, ICT, Broadcasting and Communications Committee, obtained from the Korea Information Society Development Institute (KISDI) on the 23rd, TVING's revenue rose 26.2-fold from 15.5 billion won in 2020 to 406.8 billion won in 2025. Revenue increased to 131.5 billion won in 2021, 247.6 billion won in 2022, 326.4 billion won in 2023 and 435.5 billion won in 2024, before declining slightly last year.
The user base also grew. Mobile Index data showed that TVING's monthly active users (MAUs) in December rose from 4.21 million in 2021 to 7.34 million in 2025, an increase of 3.13 million, or 74.3%. However, MAUs include free users and therefore differ from the number of paid subscribers.
By contrast, an investigation by a joint public-private task force under the Ministry of Science and ICT, announced on the 3rd, found that TVING had only four employees dedicated to protecting personal information. The task force said TVING had identified a vulnerability in a 2024 simulated hacking exercise—access keys were stored directly in the source code—but failed to address it. After abnormal activity was detected during the breach, it took about 14 hours for the situation to be shared with the company's dedicated information security organization and top official. TVING also reported the incident to the Korea Internet & Security Agency (KISA) after the statutory deadline.
Lee said, "Isn't a company whose revenue has grown 26-fold in five years, but employs only four people to protect customer information, effectively refusing to protect its users at all?" He added, "Companies must no longer be allowed to focus solely on growth while putting user protection on the back burner."
He also urged the Ministry of Science and ICT to assess whether companies are expanding their security personnel and investments and addressing vulnerabilities, and called on the Personal Information Protection Commission (PIPC) to investigate why information on dormant and terminated accounts was retained and whether the obligation to destroy it was properly observed.
[email protected] Yoon Hong-jip Reporter