Nearly 40 mln Tving accounts compromised in massive data breach: probe调查显示,近4000万个Tving账户在大规模数据泄露事件中遭到入侵。
SEOUL, Sept. 3 (Yonhap) -- Nearly 40 million user accounts of South Korean strea...

This will let Google show Yonhap news articles that match or are related to your search
SEOUL, Sept. 3 (Yonhap) -- Nearly 40 million user accounts of South Korean streaming platform Tving were compromised in a massive data breach stemming from a hacking incident reported in June, a joint investigation showed Thursday.
The Ministry of Science and ICT announced the results of a three-month government-civilian investigation into the breach at Tving, an online video streaming platform operated by entertainment giant CJ ENM Co.
A total of 39.54 million user accounts and 361 technical assets, including source code, were found to have been compromised in the breach reported on June 1, although the account figure includes multiple accounts held by the same users, the ministry said.
Tving's logo is seen in this photo provided by the streaming platform under CJ ENM Co. (PHOTO NOT FOR SALE) (Yonhap)
Tving has since strengthened its security measures, and no signs of additional attacks have been detected so far, it noted.
By registration method, they included 7.26 million accounts registered directly with Tving, 8.63 million CJ ONE integrated membership accounts and 22.47 million accounts created through social media log-in services, including Naver, Kakao, Facebook, Apple and X.
Of the total, 22.06 million were active accounts that could be used to log in, while 17.37 million were inactive accounts, including dormant and closed accounts.
The leaked information covered 20 categories comprising 70 types of data, including names, dates of birth, mobile phone numbers, email addresses and connecting information, though the type and extent of information exposed varied depending on how users registered their accounts.
The Personal Information Protection Commission is expected to separately determine the extent of the personal data breach and decide on the amount of penalties.
Investigators found that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems.
The investigation also found that Tving failed to report the breach to the Korea Internet & Security Agency within 24 hours of detecting the incident on May 30, reporting it only on June 1 and potentially facing a fine for the delay.
Investigators warned of potential secondary damage, saying the hacker could exploit the compromised data to carry out further attacks, while leaked personal information could be used for cybercrimes such as smishing and voice phishing.
The breach could deal a setback to Tving at a time when the streaming platform has begun to improve its financial performance.
Tving posted 140.7 billion won (US$103.6 million) in sales and 6 billion won in operating profit in the second quarter, marking its first quarterly operating profit since becoming a standalone company in 2020.
ejkim@yna.co.kr (END)
Personal info of Tving users leaked
7 military officers disciplined over lax management of firearms: data
Los Angeles declares 'BTS Week' ahead of concerts
Constitutional Court rules Seoul's lack of birth registration regulations for foreigners unconstitutional
2 killed in oil products tanker fire off Incheon
(URGENT) S. Korea, U.S., Japan to conduct Freedom Edge trilateral drills Sept. 7-11: S. Korean military
S. Korean response team continues search efforts for 9 missing in Nepal floods
(2nd LD) Lee nominates 6 ministers in major Cabinet reshuffle, including finance minister
White House says U.S. policy on N. Korea unchanged, reaffirms Trump's openness to dialogue with Kim
S. Korea's Protestant church offer condolences to Nepal floods victims
Lee reaffirms commitment to replacing Korean armistice with peace regime
Trump says S. Korea, Japan, others going to Alaska to 'load up' with oil, build pipelines
Lutnick: Trump gov't considering 'targeted,' thoughtful' tariff policy for semiconductors
(3rd LD) 1 dead, 6 missing after tugboat capsizes in waters off Busan
Navy's flagship sub returns after longest voyage across Pacific
Flood-hit hydroelectric power plant construction site in Nepal
Rice paddies in border town
National conference of teachers in N. Korea
Nearly 40 mln Tving accounts compromised in massive data breach: probe
这将使谷歌能够向您展示与您的搜索匹配或相关的韩联社新闻文章。
首尔,9月3日(韩联社)——周四公布的一项联合调查显示,韩国流媒体平台Tving近4000万用户账户在6月份报告的一起黑客攻击事件引发的大规模数据泄露中遭到入侵。
科学和信息通信技术部公布了政府和民间联合对娱乐巨头 CJ ENM 公司运营的在线视频流媒体平台 Tving 的安全漏洞事件进行为期三个月的调查结果。
该部表示,在6月1日报告的泄露事件中,共有3954万个用户账户和361项技术资产(包括源代码)遭到泄露,但账户数量包括同一用户拥有的多个账户。
这张照片显示的是流媒体平台 Tving 的标志,该平台隶属于 CJ ENM 公司。(照片非卖品)(韩联社)
Tving公司指出,此后已加强了安全措施,目前尚未发现其他攻击迹象。
按注册方式划分,其中包括直接在 Tving 注册的 726 万个账户、863 万个 CJ ONE 综合会员账户以及通过社交媒体登录服务(包括 Naver、Kakao、Facebook、Apple 和 X)创建的 2247 万个账户。
其中,2206万个是可用于登录的活跃账户,1737万个是不活跃账户,包括休眠账户和已关闭账户。
泄露的信息涵盖 20 个类别,包含 70 种数据类型,包括姓名、出生日期、手机号码、电子邮件地址和连接信息,但泄露的信息类型和范围因用户注册帐户的方式而异。
个人信息保护委员会预计将另行确定个人数据泄露的范围,并决定处罚金额。
调查人员发现,一名身份不明的黑客窃取了一名开发人员的访问密钥,并利用该密钥入侵了 Tving 的内部系统。
调查还发现,Tving 在 5 月 30 日发现数据泄露事件后,并未在 24 小时内向韩国互联网安全局报告,而是在 6 月 1 日才报告,可能因此面临罚款。
调查人员警告说,可能会造成二次损害,黑客可能会利用泄露的数据进行进一步攻击,而泄露的个人信息可能会被用于网络犯罪,例如短信钓鱼和语音钓鱼。
此次数据泄露事件可能会给流媒体平台 Tving 带来挫折,而此时该平台的财务业绩已经开始好转。
Tving 第二季度销售额达 1407 亿韩元(1.036 亿美元),营业利润达 60 亿韩元,这是该公司自 2020 年成为独立公司以来首次实现季度营业利润。
ejkim@yna.co.kr (完)
Tving用户个人信息泄露
7名军官因枪支管理不善受到纪律处分:数据
洛杉矶宣布举办“BTS周”演唱会
宪法法院裁定首尔缺乏外国人出生登记规定违宪
仁川附近海域油轮起火,2人死亡
(紧急)韩国、美国、日本将于9月7日至11日举行“自由边缘”三边联合军演:韩国军方
韩国救援队继续搜寻尼泊尔洪灾中失踪的9人
(第二条)李显龙提名6位部长,进行内阁重大改组,其中包括财政部长
白宫表示美国对朝政策不变,重申特朗普对与金正恩对话持开放态度。
韩国基督教新教会向尼泊尔洪灾受害者表示慰问
李重申致力于以和平机制取代朝鲜停战协定。
特朗普称韩国、日本和其他国家将前往阿拉斯加“大量开采”石油,并修建输油管道。
卢特尼克:特朗普政府正在考虑对半导体行业实施“有针对性”、“深思熟虑”的关税政策
(3rd LD)釜山附近海域拖船倾覆,1人死亡,6人失踪
海军旗舰潜艇完成横跨太平洋的最长航程后返回。
尼泊尔受洪水侵袭的水电站建设工地
边境小镇的稻田
朝鲜全国教师大会
调查显示,近4000万个Tving账户在大规模数据泄露事件中遭到入侵。