Member IDs, names, phone numbers among leaked data; resident registration numbers, payment info not affected
Tving CEO Choi Joo-hee vows to 'overhaul security from the ground up'
The government has formed a joint public-private investigation team to probe a personal data breach at Tving, South Korea's leading streaming service, after the platform reported unauthorized external access to its member database. Tving CEO Choi Joo-hee said the company bears full responsibility for the incident and pledged to see through all efforts to compensate affected users and protect their interests.
According to the Ministry of Science and ICT, Tving filed a report on the data breach on June 1. The ministry and the Korea Internet & Security Agency immediately asked Tving to preserve relevant records and launched an investigation into the cause and scope of the incident. After convening an emergency session of its cybersecurity incident review committee, the ministry determined the breach constituted a serious incident. It decided to form a joint public-private task force in light of the large-scale data exposure and the potential for further harm.
The task force will be led by the Ministry of Science and ICT's director of information security and network policy. In addition to ministry and KISA officials, the team will include private-sector experts in digital forensics and cloud services. The ministry said it plans to release its findings after completing the investigation into the cause and scope of the breach.
Tving said in notices on its website and app that it confirmed on June 2 unauthorized access to its personal data storage database and the exfiltration of files. The leaked information includes member IDs, names, dates of birth, gender, mobile phone numbers, email addresses, connecting information (CI), duplicate registration confirmation information (DI), refund account numbers, passwords and service usage records.
Tving said some mobile phone numbers, some email addresses, refund account numbers and passwords were stored in encrypted form. The company said it does not hold resident registration numbers or active payment information, so those were not among the leaked data. However, it has not yet disclosed the exact number of affected users.
After confirming the breach, Tving blocked the attacker's IP address, updated its cloud access control policy and strengthened database access monitoring. The company also launched a comprehensive security review to prevent further damage and advised users who share the same account credentials across other services to change their passwords.
Some users have raised concerns about the exposure of CI and DI data. CI is a unique identifier assigned to users who have completed identity verification. Experts warn that when combined with other personal information, it could be exploited for identity theft or other harm.
As those concerns spread, CEO Choi offered a public apology. "I sincerely apologize for the great worry this personal data breach has caused our users," she said.
Choi acknowledged that unauthorized external access had resulted in the exposure of user personal data and that Tving bears responsibility for failing to protect that information. She said the company is committed to fulfilling its obligations on user compensation and protection.
"We will overhaul our security systems from the ground up to ensure this never happens again," Choi said.
rim@heraldcorp.com