IT·SCIENCE

Tving apologizes for data breach affecting 40 million accounts, unveils compensation plan

by
Cha Min-ju
Published : Sept. 3, 2026 - 18:27:00
    • Copy Completed!

View Korean Original

Compensation worth about 20,000 won per user to roll out next month

Security investment to reach 12 billion won annually within 5 years

Security staff to triple; company-wide security overhaul announced

From left, Cho Seong-dae, head of the network technology division; Ko Min-seok, executive vice president for human resources; Tving CEO Choi Joo-hee; and Jang Hyeon-gyeong, head of the business management division, bow in apology at a briefing on the cyberattack held Thursday. [Cha Min-ju]
From left, Cho Seong-dae, head of the network technology division; Ko Min-seok, executive vice president for human resources; Tving CEO Choi Joo-hee; and Jang Hyeon-gyeong, head of the business management division, bow in apology at a briefing on the cyberattack held Thursday. [Cha Min-ju]

Tving has issued a formal apology over a massive personal data breach and announced a compensation package for affected customers. Each customer will receive points and coupons worth about 10,000 won ($7) as well as a one-year security insurance policy.

The streaming platform also unveiled a company-wide plan to overhaul its security framework, with annual information security investment targeted to reach 12 billion won within five years and a restructuring of its organizational governance.

Tving CEO Choi Joo-hee made the announcement Thursday at a briefing on the cyberattack held at Coreana Hotel in Jongno-gu, Seoul. "We humbly accept the findings of the public-private joint investigation team and sincerely apologize to our customers for the concern and anxiety this incident has caused," she said.

Choi bowed in apology and went on to say, "Since the incident, we have cooperated faithfully with the investigation, implemented emergency security measures and worked to protect our customers. We will responsibly carry out measures to prevent a recurrence and restore the trust of our customers."

The customer compensation package announced at the briefing consists of four components: hacking and phishing security insurance, an upgrade to a premium viewing environment, Tving points, and entertainment coupons. Applications for the package will be accepted from Monday through Sept. 30, with benefits applied through Oct. 6.

The security insurance will cover customers for one year, from next month through September next year. Jang Hyeon-gyeong, head of Tving's business management division, said the policy would cover up to 3 million won ($2,190) per person for cyber financial fraud stemming from hacking or phishing, as well as online shopping scams and peer-to-peer transaction fraud.

From left, Cho Seong-dae, head of the network technology division; Ko Min-seok, executive vice president for human resources; Tving CEO Choi Joo-hee; and Jang Hyeon-gyeong, head of the business management division, bow in apology at a briefing on the cyberattack held Thursday. [Cha Min-ju]
From left, Cho Seong-dae, head of the network technology division; Ko Min-seok, executive vice president for human resources; Tving CEO Choi Joo-hee; and Jang Hyeon-gyeong, head of the business management division, bow in apology at a briefing on the cyberattack held Thursday. [Cha Min-ju]

All customers will also receive a premium viewing upgrade from next month through November, with no separate application required. Jang said the upgrade would support viewing in up to 4K resolution, expand simultaneous viewing to up to four devices per account, and provide 400 downloads for offline viewing even in poor network conditions.

Each customer will additionally receive Tving points and coupons valued at about 10,000 won in total. The package includes 5,000 won in Tving points redeemable for new movie purchases, along with an entertainment coupon — a choice of either a one-month Wavve ad-supported video-on-demand subscription (valued at 5,500 won) or a 5,000-won discount coupon for a CGV combo set.

Jang said the total value would vary depending on which compensation option a customer selects, but estimated that the average customer would receive benefits worth about 20,000 won.

Tving also announced a company-wide security overhaul built around four strategic pillars: expanding information security investment and security personnel, rebuilding its security framework on a zero-trust basis, restructuring organizational governance and security culture, and strengthening expertise through external partnerships.

Tving CEO Choi Joo-hee bows in apology at a briefing on the cyberattack held Thursday. [Cha Min-ju]
Tving CEO Choi Joo-hee bows in apology at a briefing on the cyberattack held Thursday. [Cha Min-ju]

Annual information security investment is targeted to reach up to 12 billion won within five years. "By 2030, we will expand information security investment to approximately four times the level of the previous five years to strengthen our in-house security capabilities," Choi said.

The company will also expand its security workforce. The security organization will be subdivided into product security, cloud security, enterprise IT security, and compliance security, with specialist headcount to triple over the next five years. Ko Min-seok, executive vice president for human resources, said the company currently has 9.4 security staff — 4.8 internal and 4.6 external — and plans to bring the combined total to between 25 and 30 over the next five years.

The company's foundational security principles will also be upgraded to a zero-trust model. The core of the plan involves transitioning to a company-wide security standard system that verifies authentication and access controls at each stage, and standardizing the framework so that permissions are granted only within the necessary scope. Systems and network segments will also be isolated on the assumption that internal breaches may occur, and protection for critical data will be strengthened.

Tving will also pursue a restructuring of its security governance framework and company-wide security culture. A working-level security council will be established under a structure led by the CEO, chief information security officer and chief privacy officer. Role-specific security education and practical simulation drills will also be regularized.

An external verification framework will be built through outside security experts. Central to this effort is the launch of an "Information Security Innovation Advisory Committee" reporting directly to the CEO. Ko said the committee is planned to have four members in total, with three already appointed.


chami@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ