Tving data breach: 39.54 million accounts compromised in S. Korea hack
Synopsis
Key Takeaways
Nearly 39.54 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach traced to a hacking incident first detected in May 2025, a joint government-civilian investigation revealed on Thursday, 3 September. The breach also exposed 361 technical assets, including source code, making it one of the most significant cybersecurity incidents in South Korea's entertainment sector.
Scale of the Breach
South Korea's Ministry of Science and ICT announced the findings after a three-month investigation into the incident at Tving, the online video streaming service operated by entertainment conglomerate CJ ENM Co. The 39.54 million figure includes multiple accounts held by the same users, the ministry clarified.
Breaking down the compromised accounts by registration type: 7.26 million were directly registered Tving accounts, 8.63 million were CJ ONE integrated membership accounts, and 22.47 million were created through social media log-in services including Naver, Kakao, Facebook, Apple, and X. Of the total, 22.06 million were active accounts still capable of being used to log in, while 17.37 million were inactive, dormant, or closed accounts.
What Data Was Exposed
The leaked information spanned 20 categories comprising 70 types of data, including names, dates of birth, mobile phone numbers, email addresses, and connecting information. The exact extent of exposure varied depending on how individual users had registered their accounts, investigators noted.
Authorities warned of potential secondary damage, cautioning that the hacker could exploit the stolen data to mount further attacks. Leaked personal information could also be weaponised for cybercrimes such as smishing and voice phishing, investigators said.
How the Hack Happened
Investigators determined that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems. The breach was first detected internally on 30 May, but Tving reportedly failed to notify the Korea Internet and Security Agency (KISA) within the mandatory 24-hour window, reporting it only on 1 June. The delay potentially exposes the company to a regulatory fine.
Tving has since strengthened its security infrastructure, and no signs of additional attacks have been detected as of the investigation's conclusion, the ministry said.
Regulatory and Financial Fallout
The Personal Information Protection Commission is expected to separately assess the extent of the personal data breach and determine the quantum of penalties. The regulatory scrutiny arrives at a particularly sensitive moment for Tving: the platform only recently posted its first quarterly operating profit since becoming a standalone company in 2020, recording sales of 140.7 billion won (approximately US$103.6 million) and an operating profit of 6 billion won in the second quarter. The breach could undermine user confidence and set back its financial recovery.
What Comes Next
With investigators flagging the risk of secondary cyberattacks, affected users are being urged to change passwords and remain vigilant against phishing attempts. The outcome of the Personal Information Protection Commission's penalty proceedings will be closely watched as a benchmark for how South Korea holds major platforms accountable for data security lapses.