361 development projects leaked, raising risk of secondary attacks; 20 categories of personal data compromised; all developers had access to breached keys; monitoring gaps and delayed breach report also draw fire
About 40 million user accounts were exposed in the Tving personal data breach, an investigation has found. The leak covered up to 70 types of personal information across 20 categories per account — including phone numbers, email addresses, dates of birth and payment histories — raising concerns about secondary harm to affected users.
The intrusion was made possible by inadequate management of developer access keys, which allowed hackers to penetrate Tving's internal systems. The company also lacked monitoring for abnormal activity, and its delayed reporting of the breach after discovery draws fire.
The Ministry of Science and ICT announced the findings Thursday at a briefing on the results of a joint public-private investigation into the Tving breach, held at Government Complex Seoul in Jongno-gu.
The damage falls into two broad categories: leaked technical assets and leaked user information. Analysis of security logs from Tving's development environment showed that 361 development projects — totaling 30.35 gigabytes — were stolen. Those projects contained technical assets used to run and manage the platform, including algorithms for personalized content recommendations and search, user management and authentication systems, payment management, and paid service operations.
The investigation team determined that hackers could analyze the stolen development projects to identify vulnerabilities and potentially exploit them in follow-on attacks, creating a risk of secondary harm.
On the user information side, about 39.54 million accounts were compromised in total, including duplicates: about 22.06 million active login-enabled accounts, about 17.37 million inactive accounts — comprising about 8.5 million dormant accounts and about 8.87 million withdrawn accounts — and about 110,000 test accounts.
The leaked data spanned 20 categories and 70 types of information, including user IDs, passwords (one-way encrypted), CJ Group integrated IDs, full names, mobile phone numbers, email addresses, dates of birth, and connection information (CI, a unique personal identifier used in place of resident registration numbers).
Some data, including phone numbers and email addresses, was leaked in encrypted form, but because the encryption keys were also stolen, investigators concluded the exposure was equivalent to plaintext.
The investigation team said the leak of phone numbers, email addresses and other user data creates a risk of secondary harm through smishing and voice phishing, as well as potential illegal trading and distribution of the data on the dark web.
At the root of the mass data breach was a comprehensive failure of Tving's personal data protection practices. The company also failed to report the cyberattack within the legally required 24-hour window.
Specifically, hackers stole a set of development-environment access keys that had been granted to all developers, allowing them to take all 361 development projects.
In addition, 43 of the 361 stolen projects contained production-environment access keys stored in source code, which enabled access to the production environment. During that process, investigators confirmed that login credentials — including IDs and passwords — for the database storing user information had been saved in plaintext without encryption.
A second attempt to exfiltrate data followed the first, but unlike the first intrusion, the second did not trigger an anomaly alert from excessive database server load, leaving Tving unaware.
In response, the Ministry of Science and ICT called on Tving to establish and regularly audit a key management, control and access-rights framework; strengthen monitoring systems for abnormal activity and bulk data queries; and secure dedicated information security personnel — currently just four staff members, excluding contractors — along with adequate budget.
Tving also faces a fine for violating the Act on Promotion of Information and Communications Network Utilization and Information Protection, which requires companies to report cyberattacks to the Ministry of Science and ICT or the Korea Internet & Security Agency within 24 hours of discovery.
ko@heraldcorp.com