It has been confirmed that 361 technical assets, including source code, and approximately 39.54 million user accounts were leaked from the online video streaming (OTT) platform Tving.
The Ministry of Science and ICT announced the results of an investigation into the Tving security breach conducted by a joint public-private investigation team at the Government Complex-Seoul today (the 3rd).
The leaked personal information includes 20 categories (70 types), such as names, dates of birth, mobile phone numbers, email addresses, and connection information (CI).
The investigation found that passwords were encrypted in a one-way manner and could not be decrypted.
However, mobile phone numbers and email addresses were leaked along with their encryption keys, which is considered to be virtually identical to a plaintext leak.
The Personal Information Protection Commission will separately finalize the detailed scale of the personal information leak.
Regarding the damage to technical assets, 361 development projects including source code (totaling 30.35 GB) were leaked.
The investigation team determined that an attacker stole a developer's "development environment access key" to infiltrate the internal system.
They also pointed out that Tving's company-wide information protection management system was generally lax, citing shortcomings such as inadequate key management systems, a lack of monitoring, and an insufficient workforce dedicated to information protection.
Failure to address vulnerabilities discovered during a 2024 penetration test was also cited as a problem.
It was also confirmed that Tving failed to meet the statutory reporting deadline after detecting the security breach.
Tving detected the security breach at 10:10 AM on May 31, but reported it to the Korea Internet & Security Agency (KISA) at 3:08 PM on June 1.
This was reported more than 24 hours after the time of detection.
The Ministry of Science and ICT plans to impose a fine of up to 30 million won for violations of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.
The ministry has demanded that Tving submit a recurrence prevention implementation plan by this month.
It plans to begin inspecting the implementation status starting in January next year.
※
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.