[Anchor]
Investigations have revealed that more than 39 million personal information records were leaked from the over-the-top streaming service TVING. This means all accounts, including those of withdrawn members, were compromised. A government investigation team pointed out that TVING's information security system was thoroughly inadequate overall.
This is reporter Choi Seung-hun.
[Reporter]
The government joint public-private investigation team announced that a total of 39.54 million accounts were leaked from TVING.
The leak affected all accounts on TVING, including current users as well as dormant and withdrawn accounts.
This included integrated CJ ONE members as well as simplified registration accounts created via Naver, Kakao, and others.
Since a single person could create accounts through multiple paths, additional verification is needed to determine the exact number of actual victims.
A total of 20 items, including names and dates of birth, were leaked. Notably, mobile phone numbers and email addresses were leaked alongside their encryption keys.
Core technologies that TVING was developing were also breached.
[Lim Jung-gyu / Director General for Information Protection and Network Policy, Ministry of Science and ICT: Technical assets for operating and managing OTT services—such as user-customized content recommendation and search algorithms, and paid service operations—were included.]
The hacker accessed the development system using stolen access keys, which contained unencrypted operation system access keys left intact inside.
It was confirmed that the hacker, having entered the operation system, accessed user information and siphoned it off entirely to an overseas account.
The investigation team stated that the access keys were not encrypted at all, and proper inspection procedures for issuance and revocation were lacking.
They pointed out that TVING neglected access key vulnerabilities discovered during a mock hacking test two years ago, and that the overall information protection system was substandard, with only 4 security personnel compared to 149 development staff.
TVING acknowledged the findings of the investigation and bowed its head.
[Choi Joo-hee / CEO of TVING: As CEO, I feel a heavy responsibility for failing to provide a secure service, and I sincerely bow my head and apologize.]
TVING announced plans to expand investments in information security, alongside a compensation package that includes hacking and phishing insurance guaranteeing up to 3 million won for one year, subscription plan upgrades, and 5,000 won each in points and coupons.
The Ministry of Science and ICT decided to impose fines on TVING for missing the statutory 24-hour reporting deadline, while police are investigating how the initial access keys were stolen and locating the overseas servers.
(Camera: Cho Choon-dong, Kim Hak-mo | Video Editing: Shin Se-eun | Design: Han Heung-soo, Kang Yoon-jung)
※
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.