Tving Data Breach Exposes 39.54 Million Accounts, Including Names, Passwords and Phone Numbers
Translated from Korean and summarized by DistantNews. Read the original for the full story.
At a glance
- South Korean streaming service Tving exposed data from 39.54 million active, dormant, deleted and test accounts, according to a government investigation.
- The leaked information covered 20 categories, including names, phone numbers, IDs, passwords, birth dates, payment histories and linked identification data.
- Hackers also stole 361 development projects containing source code and used access keys embedded in that code to reach user databases; Tving plans increased security spending and compensation for affected customers.
Tving’s security failure exposed far more than customer accounts. A government investigation found that hackers obtained personal information from 39.54 million accounts and also stole source code, recommendation and search algorithms, and other core technical assets.
The total included 22.06 million active accounts, 17.37 million dormant or deleted accounts, and 110,000 test accounts. The figure counts accounts rather than unique individuals, and South Korea’s Personal Information Protection Commission will determine the actual number of people affected and the detailed scope of the leak.
The stolen information covered 20 categories, or 70 types of data. They included names, mobile phone numbers, user IDs, passwords, birth dates, linked identification information and payment records. Investigators also identified 361 development projects, totaling 30.35 gigabytes, that contained source code written or being developed by Tving engineers.
Investigators said weak management of keys used to access Tving’s development and operating environments enabled the breach. Hackers used a stolen development-environment key to enter the development system and extract all 361 projects in two attacks. Forty-three keys that could access the operating environment appeared directly in source code or remained unencrypted in configuration files. The attackers used some of them to access databases containing user information twice.
Tving detected an abnormal alert during the first attack on May 30, when server CPU usage reached 100%, and blocked the activity. It did not immediately detect a second attack the following day, when the hackers created a separate virtual server. Investigators criticized Tving for giving every developer access to all projects, lacking real-time monitoring of networks and data flows, and maintaining only about four dedicated information-security staff apart from outsourced workers. The company apologized again and promised to quadruple security investment by 2030 compared with the previous five years, triple specialist staffing over five years, provide every affected customer with 5,000 won in Tving points, and compensate up to 3 million won for cyber-financial fraud linked to hacking or phishing. The science ministry also plans to impose an administrative fine, saying Tving reported the breach more than 24 hours after detecting it.
I sincerely apologize for causing concern and anxiety to our customers through this security breach.
Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.