Tving data breach: 39.54 million accounts compromised in S. Korea hack

Share:
Audio Loading voice…
Tving data breach: 39.54 million accounts compromised in S. Korea hack

Synopsis

A single stolen developer access key unlocked nearly 39.54 million Tving accounts and 361 technical assets — including source code — in what a joint South Korean government-civilian probe has confirmed as one of the country's largest streaming-platform data breaches. The timing is brutal: Tving had just posted its first-ever quarterly operating profit as a standalone company.

Key Takeaways

39.54 million Tving user accounts and 361 technical assets , including source code, were compromised in the breach.
An unidentified hacker stole a developer's access key to infiltrate Tving's internal systems, first detected on 30 May .
Leaked data spans 20 categories and 70 types , including names, phone numbers, email addresses, and dates of birth.
Tving faces a potential fine for failing to report the breach to KISA within the mandatory 24-hour window.
The Personal Information Protection Commission will separately determine penalties for the personal data exposure.
The breach threatens to derail Tving's financial recovery after its first quarterly operating profit since becoming standalone in 2020 .

Nearly 39.54 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach traced to a hacking incident first detected in May 2025, a joint government-civilian investigation revealed on Thursday, 3 September. The breach also exposed 361 technical assets, including source code, making it one of the most significant cybersecurity incidents in South Korea's entertainment sector.

Scale of the Breach

South Korea's Ministry of Science and ICT announced the findings after a three-month investigation into the incident at Tving, the online video streaming service operated by entertainment conglomerate CJ ENM Co. The 39.54 million figure includes multiple accounts held by the same users, the ministry clarified.

Breaking down the compromised accounts by registration type: 7.26 million were directly registered Tving accounts, 8.63 million were CJ ONE integrated membership accounts, and 22.47 million were created through social media log-in services including Naver, Kakao, Facebook, Apple, and X. Of the total, 22.06 million were active accounts still capable of being used to log in, while 17.37 million were inactive, dormant, or closed accounts.

What Data Was Exposed

The leaked information spanned 20 categories comprising 70 types of data, including names, dates of birth, mobile phone numbers, email addresses, and connecting information. The exact extent of exposure varied depending on how individual users had registered their accounts, investigators noted.

Authorities warned of potential secondary damage, cautioning that the hacker could exploit the stolen data to mount further attacks. Leaked personal information could also be weaponised for cybercrimes such as smishing and voice phishing, investigators said.

How the Hack Happened

Investigators determined that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems. The breach was first detected internally on 30 May, but Tving reportedly failed to notify the Korea Internet and Security Agency (KISA) within the mandatory 24-hour window, reporting it only on 1 June. The delay potentially exposes the company to a regulatory fine.

Tving has since strengthened its security infrastructure, and no signs of additional attacks have been detected as of the investigation's conclusion, the ministry said.

Regulatory and Financial Fallout

The Personal Information Protection Commission is expected to separately assess the extent of the personal data breach and determine the quantum of penalties. The regulatory scrutiny arrives at a particularly sensitive moment for Tving: the platform only recently posted its first quarterly operating profit since becoming a standalone company in 2020, recording sales of 140.7 billion won (approximately US$103.6 million) and an operating profit of 6 billion won in the second quarter. The breach could undermine user confidence and set back its financial recovery.

What Comes Next

With investigators flagging the risk of secondary cyberattacks, affected users are being urged to change passwords and remain vigilant against phishing attempts. The outcome of the Personal Information Protection Commission's penalty proceedings will be closely watched as a benchmark for how South Korea holds major platforms accountable for data security lapses.

Point of View

Yet Tving still missed the mandatory 24-hour breach-notification window, suggesting compliance culture lagged behind regulatory intent. The deeper concern is the secondary-attack warning: with 70 types of personal data now potentially in circulation, the breach's true cost may only become visible months from now, in a wave of smishing and phishing incidents. Regulators must ensure that penalty proceedings are swift and proportionate enough to deter similar negligence from other large platforms.
NationPress
3 Sept 2026

Frequently Asked Questions

What happened in the Tving data breach?
An unidentified hacker stole a developer's access key and used it to infiltrate the internal systems of South Korean streaming platform Tving, compromising 39.54 million user accounts and 361 technical assets including source code. The breach was first detected on 30 May, with the full scale confirmed by a joint government-civilian investigation announced on 3 September.
How many accounts were affected and what data was leaked?
A total of 39.54 million accounts were compromised, of which 22.06 million were active. The leaked data covered 20 categories and 70 types of information, including names, dates of birth, mobile phone numbers, email addresses, and connecting information.
Why could Tving face a regulatory fine?
Tving detected the breach on 30 May but did not notify the Korea Internet and Security Agency within the mandatory 24-hour window, reporting it only on 1 June. This delay is a violation of South Korean cybersecurity regulations and could result in a fine.
What risks do affected Tving users face?
Investigators have warned of secondary damage: the hacker could use the stolen data to mount further cyberattacks, and leaked personal information could be exploited for smishing (SMS phishing) and voice phishing scams. Affected users are advised to change passwords and be alert to suspicious communications.
How does the breach affect Tving's business?
The breach arrives just as Tving posted its first quarterly operating profit since becoming a standalone company in 2020, recording 140.7 billion won in sales and 6 billion won in operating profit in the second quarter. The reputational and regulatory fallout could undermine user trust and slow its financial recovery.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 week ago
  2. 2 months ago
  3. 6 months ago
  4. 9 months ago
  5. 9 months ago
  6. 11 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google