Nearly 40 mil. Tving accounts compromised in massive data breach: probe调查显示,近4000万个电视账户在大规模数据泄露事件中遭到入侵。
Nearly 40 million user accounts of Korean streaming platform Tving were compromised in a massive data breach stemming from a hacking incident repor...

A joint investigation found that nearly 40 million Tving user accounts were compromised in a massive data breach tied to a hacking incident reported in June. The Ministry of Science and ICT said 39.54 million accounts and 361 technical assets, including source code, were exposed, and that Tving has strengthened security with no further attacks detected so far. Investigators said an unidentified hacker used a stolen developer access key to enter internal systems. The company also may face a fine for failing to report the breach within 24 hours.
The compromised data covered 39.54 million user accounts and 361 technical assets, including source code.
The leaked information spanned 20 categories and 70 types of data, including names, dates of birth, mobile phone numbers, email addresses and connecting information.
Investigators said the hacker stole a developer’s access key and used it to infiltrate Tving’s internal systems.
Tving reported the incident on June 1 after detecting it on May 30, potentially exposing it to a fine for the delay.
Tving posted 140.7 billion won in sales and 6 billion won in operating profit in the second quarter, its first quarterly operating profit since becoming a standalone company in 2020.
Published Sep 3, 2026 2:19 pm KST
Updated Sep 3, 2026 2:21 pm KST
Tving's office in Seoul's Mapo District, Thursday / Newsis
Nearly 40 million user accounts of Korean streaming platform Tving were compromised in a massive data breach stemming from a hacking incident reported in June, a joint investigation showed Thursday.
The Ministry of Science and ICT announced the results of a three-month government-civilian investigation into the breach at Tving, an online video streaming platform operated by entertainment giant CJ ENM Co.
A total of 39.54 million user accounts and 361 technical assets, including source code, were found to have been compromised in the breach reported on June 1, although the account figure includes multiple accounts held by the same users, the ministry said.
Tving has since strengthened its security measures, and no signs of additional attacks have been detected so far, it noted.
By registration method, they included 7.26 million accounts registered directly with Tving, 8.63 million CJ ONE integrated membership accounts and 22.47 million accounts created through social media log-in services, including Naver, Kakao, Facebook, Apple and X.
Of the total, 22.06 million were active accounts that could be used to log in, while 17.37 million were inactive accounts, including dormant and closed accounts.
The leaked information covered 20 categories comprising 70 types of data, including names, dates of birth, mobile phone numbers, email addresses and connecting information, though the type and extent of information exposed varied depending on how users registered their accounts.
The Personal Information Protection Commission is expected to separately determine the extent of the personal data breach and decide on the amount of penalties.
Investigators found that an unidentified hacker stole a developer's access key and used it to infiltrate Tving's internal systems.
The investigation also found that Tving failed to report the breach to the Korea Internet & Security Agency within 24 hours of detecting the incident on May 30, reporting it only on June 1 and potentially facing a fine for the delay.
Investigators warned of potential secondary damage, saying the hacker could exploit the compromised data to carry out further attacks, while leaked personal information could be used for cybercrimes such as smishing and voice phishing.
The breach could deal a setback to Tving at a time when the streaming platform has begun to improve its financial performance.
Tving posted 140.7 billion won ($103.6 million) in sales and 6 billion won in operating profit in the second quarter, marking its first quarterly operating profit since becoming a standalone company in 2020.
联合调查发现,近4000万Tving用户账户在一次大规模数据泄露事件中遭到入侵,该事件与6月份报告的一起黑客攻击事件有关。韩国科技信息通信部表示,共有3954万个账户和361项技术资产(包括源代码)被泄露,Tving已加强安全措施,目前尚未发现进一步攻击。调查人员称,一名身份不明的黑客使用窃取的开发者访问密钥入侵了内部系统。该公司还可能因未在24小时内报告此次数据泄露事件而面临罚款。
泄露的数据涉及 3954 万个用户帐户和 361 项技术资产,包括源代码。
泄露的信息涵盖 20 个类别和 70 种数据类型,包括姓名、出生日期、手机号码、电子邮件地址和联系方式。
调查人员称,黑客窃取了一名开发人员的访问密钥,并利用该密钥入侵了 Tving 的内部系统。
Tving 于 5 月 30 日发现该事件,但直到 6 月 1 日才上报,这可能使其面临因延误而产生的罚款。
Tving 第二季度销售额达 1407 亿韩元,营业利润达 60 亿韩元,这是该公司自 2020 年成为独立公司以来首次实现季度营业利润。
发布于2026年9月3日下午2:19(韩国标准时间)
更新于2026年9月3日下午2:21(韩国标准时间)
周四,Tving在首尔麻浦区的办公室 / Newsis
周四公布的一项联合调查显示,韩国流媒体平台Tving近4000万用户账户在6月份报告的一起黑客攻击事件引发的大规模数据泄露中遭到入侵。
科学和信息通信技术部公布了政府和民间对Tving(由娱乐巨头CJ ENM公司运营的在线视频流媒体平台)安全漏洞事件进行为期三个月的调查结果。
该部表示,在6月1日报告的数据泄露事件中,共有3954万个用户账户和361项技术资产(包括源代码)遭到泄露,但账户数量包括同一用户拥有的多个账户。
Tving公司指出,此后已加强了安全措施,目前尚未发现其他攻击迹象。
按注册方式划分,其中包括直接在 Tving 注册的 726 万个账户、863 万个 CJ ONE 综合会员账户以及通过社交媒体登录服务(包括 Naver、Kakao、Facebook、Apple 和 X)创建的 2247 万个账户。
其中,2206万个是可用于登录的活跃账户,1737万个是不活跃账户,包括休眠账户和已关闭账户。
泄露的信息涵盖 20 个类别,包含 70 种数据类型,包括姓名、出生日期、手机号码、电子邮件地址和连接信息,但泄露的信息类型和范围因用户注册帐户的方式而异。
个人信息保护委员会预计将另行确定个人数据泄露的范围,并决定处罚金额。
调查人员发现,一名身份不明的黑客窃取了一名开发人员的访问密钥,并利用该密钥入侵了 Tving 的内部系统。
调查还发现,Tving 在 5 月 30 日发现数据泄露事件后,并未在 24 小时内向韩国互联网安全局报告,而是在 6 月 1 日才报告,可能因此面临罚款。
调查人员警告说,可能会造成二次损害,黑客可能会利用泄露的数据进行进一步攻击,而泄露的个人信息可能会被用于网络犯罪,例如短信钓鱼和语音钓鱼。
此次数据泄露事件可能会给流媒体平台 Tving 带来挫折,而此时该平台的财务业绩已经开始好转。
Tving 第二季度销售额达 1407 亿韩元(1.036 亿美元),营业利润达 60 亿韩元,这是该公司自 2020 年成为独立公司以来首次实现季度营业利润。