Science Ministry: Tving Data Breach Exposed 39.54 Million Accounts and 361 Development Projects
Translated from Korean and summarized by DistantNews. Read the original for the full story.
At a glance
- A South Korean government investigation found that a breach at streaming service Tving exposed data linked to 39.54 million accounts, including active, dormant, deleted and test accounts.
- The stolen information covered 20 categories and 70 types of data, while 361 development projects containing source code and core recommendation, search and authentication technologies were also taken.
- Investigators attributed the breach to poorly managed access keys, including 43 AWS keys stored in source code or unencrypted settings, and said Tving reported the incident about 29 hours after detecting it.
A data breach at South Korean streaming service Tving exposed information linked to 39.54 million accounts and 361 internal development projects, according to a joint public-private investigation.
The Ministry of Science and ICT presented its findings on Sept. 3 after forming an investigative team immediately after Tving reported the intrusion on June 3. The account total included 22.06 million active accounts, 17.37 million dormant or deleted accounts and 1.1 million test accounts. The figure includes cases where one person held multiple accounts. The Personal Information Protection Commission will determine the number of people affected and the detailed scale of the personal-data leak.
The exposed information covered 20 categories, or 70 types of data, including names, mobile phone numbers, usernames, passwords, dates of birth, connecting information and payment histories. Some phone numbers and email addresses had been encrypted, but the encryption keys were also exposed and could be used to decrypt them. Passwords remained in one-way encrypted form and could not be decrypted.
The breach also reached Tvingโs technical assets. Investigators said hackers took 361 development projects, totaling 30.35 gigabytes, containing source code for systems under construction or development. The material included personalized content recommendation and search algorithms, as well as user-management and authentication systems.
Investigators reconstructed an attack in which hackers used a previously stolen development-environment key to enter Tvingโs development system and extract all 361 projects in two attacks. The source code contained 43 AWS operating-environment keys either in plain text or as unencrypted settings. Hackers used two of those keys to reach a database containing user information.
The first attack on May 30 triggered an alert when server CPU usage reached 100%, and Tving blocked the activity. The following day, however, the hackers created a separate virtual server and used it as a channel to remove 24 gigabytes of personal information. Investigators could not determine how the original development key reached the attackers.
The ministry said Tving had given all developers access to every project instead of limiting access according to work needs. It also criticized the company for failing to fix a vulnerability identified during a 2024 penetration test, when access keys were found stored directly in source code. The ministry plans to impose a fine because Tving reported the breach to the Korea Internet and Security Agency about 29 hours after first recognizing it, beyond the legally required 24-hour period.
Based on the investigation results, we will require Tving to submit an implementation plan for preventive measures and will inspect whether Tving carries them out.
Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.