CONSUMER

CJ data breach widens: Tving leak hits 13 million users, employees also at risk

by
Kang Seung-yeon
Published : June 12, 2026 - 16:23:49
    • Copy Completed!

View Korean Original

Leak of online identifier CI deepens concerns

Some members report SNS accounts hacked or locked

Employees warned to change passwords as work details may be exposed

A CJ ONE integrated membership account affected by the Tving data breach [Provided by reader]
A CJ ONE integrated membership account affected by the Tving data breach [Provided by reader]

A cascading series of personal data breaches at CJ Corp has thrown consumers into alarm. Experts say the situation is far from trivial, particularly because the leaked data includes CI (connection information) and DI (duplicate registration information) — online identifiers that can be used to link individuals across platforms.

According to industry sources, Tving, a streaming subsidiary of CJ ENM, began sequentially locking accounts June 10 for CJ ONE integrated membership users who had not changed their passwords following a data breach that occurred June 2. The number of affected users is estimated at 13 million.

Tving members can sign up using a dedicated Tving ID or through linked accounts from CJ ONE, Naver, Kakao and other social media platforms. As a result, users who registered via a third-party platform must change their passwords directly on that platform — an added inconvenience for many.

The data exposed in the breach includes names, user IDs, dates of birth, gender, mobile phone numbers, email addresses, refund account numbers and passwords. Also among the leaked items are CI and DI, two online identifiers. CI is a linking code generated to identify users who have completed identity verification — effectively functioning as an online equivalent of a resident registration number. When combined with other leaked details such as names, dates of birth, phone numbers and email addresses from separate breaches, CI can be used to build a comprehensive profile of an individual, significantly raising the stakes.

The breach also exposes victims to phishing and smishing scams. In response, Tving warned June 10 that "phishing attempts impersonating Tving via phone calls, text messages and emails are occurring on an ongoing basis," urging users to exercise caution to avoid falling victim.

Reports of secondary harm are already circulating in online communities, where users say their Facebook, Instagram and other social media accounts have been hacked or locked following the Tving data breach.

CJ Group employees are also being targeted. A significant number of staff use Tving free of charge through CJ ONE accounts as a company welfare benefit. CJ Group recently sent an internal email advising employees to strengthen account security and change their passwords, warning that their employment information may have been exposed in the breach.

The turmoil is compounding rapidly, coming barely a month after a separate incident in which the personal data of more than 330 current and former female employees was leaked. Although CJ Group has set up a task force to support personal data protection, complaints are mounting that the response has been too passive. Some victims allege that secondary damage is already occurring, and a number of those affected are reportedly preparing legal action.


spa@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ