Editorial: Nearly 40 million TVING accounts exposed, revealing a streaming giant’s lax data security
Translated from Korean and summarized by DistantNews. Read the original for the full story.
At a glance
- A joint public-private investigation team said 39.54 million TVING accounts were leaked in an incident disclosed on Sept. 3, including 22.06 million active accounts that could log in.
- The exposed information included usernames, passwords, names, phone numbers and email addresses, while encryption keys for phone numbers and emails were also stolen.
- The editorial says the breach resulted from stolen developer access keys and failures to respond to an earlier warning, and calls for stronger legal and administrative accountability.
Nearly every account stored by South Korean streaming service TVING appears to have been exposed. A joint investigation team under the Ministry of Science and ICT said 39.54 million accounts were leaked in an incident disclosed on Sept. 3, including 22.06 million active accounts that could still log in.
Because one person can create multiple accounts, TVING estimates that information belonging to 19.53 million people was affected. The scale places the breach among South Korea’s largest recent security incidents, following breaches involving Coupang and SK Telecom.
The leaked data covered 20 categories, including usernames, passwords, names, mobile phone numbers and email addresses. Although the phone numbers and email addresses were encrypted, the keys needed to unlock them were leaked as well. The editorial argues that this made the exposure effectively equivalent to a release of the original information.
The damage may extend beyond personal data. Investigators said 361 technology assets, including content recommendation algorithms and paid-service operations, were also taken. That could lead to intellectual-property losses.
The breach began when an attacker obtained a developer’s access key and entered TVING’s internal systems. An alarm reportedly sounded during the hacking attempt, but the company treated it as a routine system problem and took no meaningful action. The editorial also points to a structure in which a single stolen key could open access to an entire project. A 2024 penetration test had identified weaknesses in access-key management, but TVING did not correct them.
The investigation team warned that the leaked information could be combined with other data for smishing or phishing. The editorial calls for continued monitoring of secondary harm, a review of the country’s ISMS certification and audit system, and the strongest available legal and administrative penalties against TVING.
Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.