DistantNews
Support us

TVING investigation finds all 39.54 million accounts were compromised

From Dong-A Ilbo · () Korean

Translated from Korean and summarized by DistantNews. Read the original for the full story.

At a glance

News Official statement Under investigation
  • A joint investigation found that 39.54 million TVING accounts were exposed after hackers stole a developer’s access key and entered the streaming platform’s internal systems.
  • The leaked data included personal information and 361 development projects containing core source code; investigators found no evidence so far of a further attack or dark-web distribution.
  • TVING announced customer compensation and plans to roughly quadruple information-security investment by 2030 and triple its specialist security workforce within five years.

A stolen developer access key gave hackers a route into TVING’s internal systems and exposed information linked to 39.54 million accounts, a joint South Korean government and private-sector investigation found.

The incident began on May 30. TVING detected signs of unauthorized access and data queries while examining a database server overload, then reported the breach to the Korea Internet and Security Agency on June 1. Investigators spent more than three months conducting digital forensics on nine developer devices and reviewing the company’s information-security controls.

The exposed accounts included 22.06 million active accounts, 17.37 million inactive or deleted accounts, and 110,000 test accounts. The total exceeded an earlier publicly known figure of 19.54 million because the initial report used a different calculation method and removed duplicate accounts. Investigators found that some users held as many as 13 accounts across different signup routes.

The leaked information covered up to 20 categories and 70 types of data, including usernames, passwords, names, phone numbers, email addresses, birth dates and linked identification information. Passwords had one-way encryption, but phone numbers and email addresses were exposed with encryption keys, creating a risk that they could be decrypted. The hackers also took 361 development projects, totaling 30.35 gigabytes, containing recommendation and search algorithms, user authentication systems and payment-management logic.

Investigators said the attackers found 43 additional production-environment access keys stored in plain text in source code. TVING also lacked effective key management, real-time monitoring of network and data flows, and sufficiently limited access rights. An alert triggered by CPU usage reaching 100% helped reveal the intrusion, but the investigation said the breach might have been detected much later without it. Police are investigating how the first access key was stolen and who carried out the attack.

TVING announced an insurance package and coupons for affected customers. It also said it would increase information-security investment by about four times by 2030, compared with the previous five years, and expand its security workforce to roughly three times its current level within five years.

We verified scenarios including phishing, malware, supply-chain attacks, the sharing or misuse of access keys, and the exploitation of system vulnerabilities, but could not find evidence to prove them because the relevant log retention periods had elapsed.

· Joint investigation teamInvestigators explained why they could not determine how the first developer access key was stolen.
About this summary

Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.