News

39.54 Million TVING Accounts Compromised... The Compensation Plan Offered Amid Apology

[Anchor]

Account information for 39.54 million accounts registered on the online video streaming service TVING has been leaked. Due to lax management, 20 items including names, mobile phone numbers, and dates of birth were leaked, and even core technologies under development were stolen.

Reporter Choi Seung-hun has the details.

[Reporter]

The government's joint public-private investigation team announced that a total of 39.54 million TVING accounts were leaked.

All accounts on TVING, including dormant and withdrawn accounts as well as current users, were compromised.

This includes CJ ONE integrated members as well as simplified login accounts created through Naver, Kakao, and others.

Since a single person could create multiple accounts through various channels, additional verification is needed to determine the exact number of actual victims.

A total of 20 items, including names and birthdays, were leaked. Notably, encryption keys for mobile phone numbers and email addresses were leaked together.

Core technologies that TVING was developing were also compromised.

[Lim Jung-gyu / Director General for Information Protection and Network Policy, Ministry of Science and ICT: Technical assets for operating and managing OTT services, such as user-customized content recommendation and search algorithms and paid service operations, were included.]

The hacker used the stolen access keys to enter the development system, which contained unencrypted operation system access keys left intact.

It was confirmed that the hacker, having entered the operation system, accessed user information and siphoned it off entirely to an overseas account.

The investigation team stated that the access keys were not encrypted at all, and inspection procedures such as issuance and revocation were virtually non-existent.

They pointed out that vulnerabilities in access keys were discovered during a mock hacking exercise two years ago but left neglected, and the overall information protection system was inadequate, with only 4 security personnel compared to 149 development staff.

TVING bowed its head, stating that it accepts the investigation results.

[Choi Joo-hee / CEO of TVING: As CEO, I feel a heavy responsibility for failing to provide secure services, and I sincerely bow my head and apologize.]

TVING announced a compensation plan that includes a hacking and phishing insurance policy guaranteeing up to 3 million won for one year, a subscription plan upgrade, and 5,000 won each in points and coupons, alongside plans to expand investments in information protection.

The Ministry of Science and ICT decided to impose a fine on TVING, stating that its report exceeded the legal deadline of 24 hours, while the police are investigating how the initial access keys were stolen and the location of the overseas servers.

(Video Reported by Cho Choon-dong, Kim Hak-mo | Video Edited by Shin Se-eun | Design by Han Heung-soo, Kang Yoon-jung)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS. All rights reserved. 무단 전재, 재배포 및 AI학습 이용 금지

Most Read