39.54 million Tving streaming accounts compromised in South Korea
In South Korea, a hacker attack on the Tving streaming platform compromised 39.54 million user accounts and 361 technical assets, including source code. The Ministry of Science and ICT reported the results of a three-month joint investigation by government agencies and civilian experts, Korea Herald writes.
The incident was reported on June 1. Investigators established that an unidentified hacker stole an access key belonging to one of the developers and used it to penetrate the service’s internal systems. Police are investigating, but the attacker’s identity and the country from which the attack was carried out have not yet been established. According to the investigation, the compromised data was transferred to accounts located abroad.
Which accounts were affected
Among the compromised accounts were 7.26 million accounts registered directly with Tving, 8.63 million accounts of the integrated CJ ONE program, and 22.47 million accounts created through authorization via Naver, Kakao, Facebook, Apple and X.
Of the total, 22.06 million accounts were active and could be used for login. Another 17.37 million were inactive records, including inactive and closed ones. The ministry stressed that the figure includes multiple accounts that may have belonged to a single user.
More current news is available on the UA.News Telegram channel Telegram.
What data was leaked
The leak covered 20 categories and 70 types of data, including names, dates of birth, mobile phone numbers, email addresses and connection data. The type and volume of disclosed information differed depending on the user’s registration method.
The Personal Information Protection Commission is to separately determine the scale of the personal data leak and the amount of possible sanctions. The investigation also found that Tving detected the incident on May 30 but notified the Korea Internet & Security Agency only on June 1, rather than within 24 hours. The company may face a fine for the delay.
According to the Ministry of Science and ICT, Tving has strengthened its security measures, and no signs of new attacks have currently been detected. At the same time, investigators warned that the compromised information could be used for further cyberattacks, smishing and telephone fraud.