News

Tving User Accounts Leak 39.54 Million Records… Encryption Keys Also Breached

Tving User Accounts Leak 39.54 Million Records… Encryption Keys Also Breached
It has been confirmed that 361 technical assets containing source code and approximately 39.54 million user accounts were leaked from the online video streaming (OTT) platform Tving.

The Ministry of Science and ICT announced the results of the investigation into the Tving security breach conducted by a public-private joint investigation team at the Government Complex-Seoul today.

The leaked personal information consists of 20 categories (70 types), including names, dates of birth, mobile phone numbers, email addresses, and connection information (CI).

The investigation showed that passwords were encrypted using one-way hashing and could not be decrypted.

However, because the encryption keys for mobile phone numbers and email addresses were leaked along with them, it was determined to be practically equivalent to a plain-text leak.

The Personal Information Protection Commission will separately determine the exact scale of the personal information leak.

Regarding the damage to technical assets, 361 development projects containing source code (totaling 30.35 GB) were leaked.

The investigation team determined that an attacker stole a developer's development environment access key and penetrated the internal systems.

They also pointed out an overall laxity in company-wide information protection management systems, including inadequate key management systems, a lack of monitoring, and an insufficient number of dedicated information protection personnel.

Failing to address vulnerabilities discovered during a 2024 penetration test was also cited as a problem.

It was also confirmed that Tving failed to meet the statutory reporting deadline after detecting the security breach.

Tving detected the security breach at 10:10 AM on May 31, but reported it to the Korea Internet & Security Agency (KISA) at 3:08 PM on June 1.

This was reported more than 24 hours after the time of detection.

The Ministry of Science and ICT plans to impose a fine of up to 30 million won for violations of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.

The Ministry of Science and ICT has required Tving to submit a recurrence prevention implementation plan by this month.

It plans to begin inspecting the implementation status starting in January next year.
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS. All rights reserved. 무단 전재, 재배포 및 AI학습 이용 금지

Most Read