Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
South Korea Finds Tving Hack Exposed 39.5 Million Accounts, Double the Original Count, After 2024 Warning Went Unfixed

South Korea's Ministry of Science and ICT announced Thursday, September 3, that a hack of streaming platform Tving compromised 39.54 million user accounts, nearly double the roughly 19.53 million figure the company had reported to the National Assembly weeks earlier, according to the Korea Herald and Yonhap.
The ministry's three-month public-private investigation, held at the Government Complex Seoul, laid out exactly how one stolen credential turned into a breach of this size. Tving, operated by entertainment conglomerate CJ ENM, first reported the incident to regulators on June 1.
One Key, Four Days, 39 Million Accounts
Investigators say an unidentified hacker stole a developer's access key and used it to break into Tving's development environment on May 29, 2026, according to The Elec. From there the attacker downloaded all 361 development projects stored in that environment, totaling 30.35 gigabytes of source code and technical assets.
Forty-three of those 361 projects contained production access keys hardcoded directly into the source code, in plaintext, according to both The Elec and Korea's Khan.co.kr. Administrative credentials in Tving's cloud storage were also stored unencrypted. That combination allowed the attacker to move from the development environment into the live production system holding the user database.
Tving's monitoring systems caught a first exfiltration attempt on May 30 and blocked it. The company's detection then failed the next day. On May 31, according to Khan.co.kr, the attacker built a virtual server, staged 24 gigabytes of user data on it, transferred that data to an external server, and deleted the virtual server to erase evidence.
Investigators examined the compromised developer's device but could not determine how the original access key was stolen in the first place. Lim Jeong-gyu, the ministry's director general for information security and network policy, said the attacker has not been identified and that police are investigating. Lim said the stolen data was moved to overseas accounts, though authorities have not yet determined which country the attack originated from.
The 2024 Warning Nobody Acted On
A 2024 penetration test flagged the hardcoded access keys in source code as a vulnerability, according to Khan.co.kr and confirmed by The Elec's reporting. The company documented it. Nothing was fixed.
Khan.co.kr also reported that Tving's dedicated information security team consisted of roughly four staff, and that the platform's setup allowed any developer to access all 361 projects rather than restricting access by role. That is a basic access-control failure, not an exotic hacking technique.
Tving also missed South Korea's mandatory 24-hour breach reporting window. The Korea Herald reported the company detected the incident on May 30 but didn't report it to the Korea Internet & Security Agency until June 1, and now faces a possible fine for the delay.
What Was Actually Taken
The leaked data covers 70 categories across 20 data types, including names, dates of birth, phone numbers, email addresses, refund bank account numbers, and government-linked connecting information (CI/DI), according to the Korea Herald and The Elec. Passwords were hashed and not reversible. Mobile numbers and emails were encrypted, but the encryption keys were leaked alongside the data, meaning investigators concluded the exposure was functionally equivalent to an unencrypted leak, per Khan.co.kr.
By signup method, 7.26 million accounts came from direct registration, 8.63 million from CJ ONE's integrated membership, and 22.47 million from social logins through Naver, Kakao, Facebook, Apple, and X. The 39.54 million figure includes duplicate accounts; one user reportedly held 13 separate Tving accounts, per Khan.co.kr.
The ministry said Tving has since strengthened its security and that no additional intrusions have been detected since. Investigators nonetheless warned of potential secondary damage, since the leaked personal information could feed smishing and voice-phishing operations, the Korea Herald reported. No secondary attacks tied to this data have been confirmed so far.
What Happens Next
South Korea's Personal Information Protection Commission will separately determine the full scope of the personal-data exposure and decide on penalties against Tving, a process the ministry said is still pending. Police are continuing to try to trace the attacker's location.
The breach adds to a run of major South Korean data incidents over the past year, including SK Telecom, KT Corp, and Coupang, according to the Korea Herald. Aju Press notes the incident comes as the National Assembly moves to expand the National Intelligence Service's role in cyber and economic security amid concerns about state-backed hacking groups, though no source in the investigation has attributed this specific attack to a state actor.
The unresolved question investigators themselves flagged: how the original developer credential was stolen in the first place. Without that answer, the specific entry point that started the chain remains open.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.