the news now

The world's news, cross-checked among reputable sources.

Nearly 40 Million Tving User Accounts Compromised in Massive Data Breach

2 sources · South Korea · 1 of them is linked to a state

Who reported this

  • Yonhap South Korea · Centre · State-affiliated · Cooperative; statutory national agency with state subsidy
  • The Korea Herald South Korea · Centre-right · Herald Corporation (Yeongpoong Group)

What the colours mean

  • Left
  • Centre-left
  • Centre
  • Centre-right
  • Right
  • A hatched block means the outlet is affiliated with, or controlled by, a state.

Political lean describes where an outlet sits within the politics of its own country. It is never a position on a single global scale.

Political lean is comparable inside one country and not across them, which is why the bar groups by country first. Publicly funded broadcasters are not marked as state-linked.

The owner of each outlet is listed as a matter of record, not as a judgement about the outlet.

Every source for this story reports from South Korea.

A joint government and civilian investigation revealed on Thursday that nearly 40 million user accounts of the South Korean streaming platform Tving were compromised in a massive data breach. The Ministry of Science and ICT reported that 39.54 million accounts and 361 technical assets, including source code, were breached in an incident first reported on June 1. The total account figure includes multiple accounts held by the same users. Of these, 22.06 million were active accounts, while 17.37 million were inactive, dormant, or closed.

The breach included 7.26 million accounts registered directly with Tving, 8.63 million CJ ONE integrated membership accounts, and 22.47 million accounts created via social media log-in services such as Naver, Kakao, Facebook, Apple, and X. Leaked data spanned 20 categories and 70 types of information, including names, dates of birth, mobile phone numbers, and email addresses. Investigators found that an unidentified hacker infiltrated Tving's internal systems by stealing a developer's access key. While the stolen data was transferred to overseas accounts, authorities have not yet identified the attacker or their country of origin.

Tving, operated by CJ ENM Co. may face a fine for failing to report the breach to the Korea Internet and Security Agency within 24 hours of detecting it on May 30. The Personal Information Protection Commission is expected to determine the extent of the breach and the resulting penalties. Investigators warned that the leaked information could be used for secondary cybercrimes, such as voice phishing and smishing.

Tving CEO Choi Ju-hee apologized for the breach and pledged to implement corrective measures. The company stated it has taken emergency security measures and plans to quadruple its cybersecurity investment. This incident occurs as Tving recently achieved its first quarterly operating profit since 2020, posting 6 billion won in operating profit on 140.7 billion won in sales for the second quarter. This breach follows other major data leaks involving South Korean companies such as SK Telecom, KT Corp. and Coupang.

How each side framed it

Centre
Outlets with a center lean focused on the technical details of the breach and the broader context of corporate data leaks in South Korea.
Centre-right
Outlets with a center-right lean provided similar factual reporting while emphasizing Tving's commitment to increasing cybersecurity investment to restore customer trust.

Sources

100% of the statements in this article were traced back to the source articles listed above.