![]() |
Following a personal data breach, TVING is significantly expanding its information security investments and specialized personnel while carrying out an across-the-board overhaul of its security architecture. After a government investigation identified shortcomings across its broader cybersecurity posture—including access key management, anomaly monitoring, and security staffing—the streaming platform decided to increase its cybersecurity investments over the next five years to roughly four times the amount spent in the preceding five years, while expanding dedicated security staff to three times the current level. For affected or concerned users, TVING will provide a compensation package that includes insurance covering up to 3 million won.
TVING held a briefing on the cyber intrusion incident at the Koreana Hotel in Gwanghwamun, Seoul, on the 3rd, announcing its plans to enhance cybersecurity and compensate users. TVING CEO Choi Ju-hui stated that the company accepts the findings of the joint public-private investigation team and will responsibly implement recurrence prevention measures to restore user trust. "We deeply reflect on this incident and will rebuild our entire security architecture from the ground up," Choi said. "We will treat information security as the platform's most vital responsibility and competitive edge, doing our utmost to regain customer trust."
The investigation identified 39.54 million leaked accounts from the incident, but because this total includes duplicate accounts, the actual number of individual users whose personal information was compromised is expected to be lower. According to the joint public-private investigation team from the Ministry of Science and ICT, the breach comprised 22.06 million active accounts, 17.37 million dormant or deleted accounts, and 110,000 test accounts. The tally included cases where a single individual held multiple accounts, with some users found to have up to 13 accounts registered. The actual number of affected individuals and final figures will be determined by the Personal Information Protection Commission.
To date, however, no actual cases of user damage or circumstances involving the illicit trade or circulation of personal information on the dark web or elsewhere have been confirmed.
According to the joint public-private investigation team, the incident escalated into a large-scale leak due to lax management of access keys and privileges, compounded by inadequate response protocols. The probe revealed that TVING exposed access keys in source code or stored them in plaintext, while granting all developers access permissions to entire projects. In addition, real-time detection and blocking mechanisms for anomalous behavior were lacking, and dedicated internal cybersecurity personnel numbered only around four, excluding outsourced contractors. It took approximately 14 hours after anomalous signs emerged for the situation to be shared with the CISO, and access key exposure vulnerabilities that were identified during mock penetration testing in 2024 had not been remediated.
TVING noted that following the breach, it took proactive measures on several vulnerabilities ahead of the government's official findings. Through a private security firm, the company conducted a full-scale vulnerability audit across 361 leaked development projects, which was verified by the investigation team, and is currently conducting further vulnerability analysis leveraging AI. The company will also expand cybersecurity investments and personnel in phases. Security spending, which stood at around 2.5 billion won last year, is projected to rise to roughly 3 billion won this year, with plans to expand it to between 10 billion and 12 billion won annually over the next five years.
As of disclosures from last year, information security personnel totaled 9.4 full-time equivalents, comprising 4.8 internal and 4.6 external staff. The discrepancy with the roughly four personnel cited in the government investigation stemmed from the official tally counting only internal dedicated staff while excluding contractors. TVING plans to increase internal security personnel to 10 by the end of this year to secure a total of 15 to 16 personnel including external staff, and further expand the team to 25 to 30 specialists over the next five years. The platform will also adopt a "Zero Trust" model that authenticates users at every access tier alongside the principle of least privilege, while strengthening AI-driven anomaly detection and automated response systems. It will also institute an Information Security Innovation Advisory Committee reporting directly to the CEO to receive third-party expert audits.
Customer compensation is focused on mitigating concerns over secondary damage stemming from the data leak. Through hacking and phishing relief insurance, the company will compensate users for up to 3 million won per person for one year against cyber financial fraud as well as scams occurring on online marketplaces and in peer-to-peer transactions. Users will also receive upgrades to premium streaming viewing conditions and 5,000 won in TVING points, along with the choice between a one-month pass for Wavve's ad-supported VOD (AVOD) tier or a CGV combo discount coupon.
Lee Seo-yeon
1
2
3
4
5
6
7