$ 44.46 € 51.71 zł 12
+15° Kyiv +17° Warsaw +28° Washington

39.5 million Tving accounts and more than 422,000 Weverse records compromised in South Korea

Lev Shevtsov 07 September 2026 07:24
39.5 million Tving accounts and more than 422,000 Weverse records compromised in South Korea

In South Korea, entertainment platforms Tving and Weverse have reported major incidents involving the security of user data. According to The Korea Herald, the Tving incident affected about 39.5 million accounts, while 422,584 records were compromised at the account identifier level in Weverse.

Tving data

South Korea’s Ministry of Science and ICT determined that accounts and source code files were compromised during the Tving incident. The affected records included 22.06 million active accounts, 17.37 million inactive accounts, including dormant and closed ones, as well as 110,000 test accounts.

The compromised information covered 20 categories and 70 data types, including names, mobile phone numbers, email addresses, dates of birth, and payment histories. Some phone numbers and email addresses were encrypted, but the encryption keys were also among the compromised data. This could potentially have allowed the information to be restored to its original form.

Secondary consequences of the incident have not been officially reported, and the identity of the attacker has not been established. At a briefing in Seoul, Tving said it intended to significantly increase investment in information security and expand its team of cybersecurity specialists. By 2030, the service plans to spend approximately four times more on security than it did over the previous five years.

More current news is available on the UA.News Telegram channel Telegram.

Weverse incident

Weverse Company, a subsidiary of Hybe, identified the security breach after receiving an external report about a possible vulnerability and apologized to users. The compromised data included internal identifiers used to distinguish accounts in the company’s systems, as well as information on purchase type, payment provider, currency, amounts and transaction times, payment statuses, and refunds.

Weverse said the internal identifiers do not contain names or contact details and cannot be used outside the company’s systems. The platform also strengthened access controls for the API that processes payment information and removed the internal identifiers to prevent their external disclosure.

Tving also announced compensation for affected users. It provides one year of insurance worth up to 3 million won, or about $2,200, per person in the event of financial fraud, fraud in online purchases, or P2P transactions resulting from hacking or phishing. The service will also provide 5,000 won in Tving points. Users must apply to receive compensation.

Read us on Telegram and Sends

Download our app