Skip to content
>_ITDITDWeb Security Platform

Security Guides

A real compensation program makes fake compensation texts believable — what TVING users should do after the breach

A breach at Korean streaming service TVING exposed data on 39.54 million accounts. From the Korean science ministry's findings: what leaked (CI, DI, refund accounts), password status, and what users should do now.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 14 min read

Who this is for: current and former users of TVING, the South Korean streaming service (including withdrawn and dormant accounts), people with family or friends in Korea, and developers and operators who handle source code and cloud credentials. This article is based on official announcements by South Korea's Ministry of Science and ICT (MSIT) and does not cover attack techniques.

What users should do now

1

Assume withdrawn and dormant accounts are included

MSIT says the leaked accounts include not only about 22.06 million active accounts but also about 8.5 million dormant and 8.87 million withdrawn accounts. Every sign-up route is included: TVING's own registration, CJ ONE integrated membership, and social logins such as Naver and Kakao. If you "used it briefly years ago" or "already deleted the account", go through these steps anyway.

2

Don't tap links in texts about compensation, refunds or checking your exposure

In a public security notice on June 3, MSIT and the Korea Internet & Security Agency (KISA) warned of smishing using phrases like "damage compensation", "check whether you were affected", "refund" and "urgent app update" to push link clicks or app installs, voice phishing posing as compensation guidance, and phishing sites placed in search results or ads. Check compensation or exposure only in the TVING app you already have, or on the TVING website you type in yourself. The notice also states that government agencies and financial institutions never ask you to install a remote-control app by phone or text (basics: what is phishing).

3

Change passwords wherever you reused them

The investigation team confirmed that passwords were leaked in one-way encrypted form and cannot be decrypted. Still, if you use the same ID and password combination elsewhere, fix those first. Change your TVING password too, and if you signed in through Naver, Kakao or another social login, turn on two-step verification there. The practical way to keep every password unique is a password manager; for choosing a second factor, see choosing multi-factor authentication.

4

If you live in Korea, turn on identity-theft alerts

CI, DI, date of birth and mobile number cannot be changed. M-Safer (msafer.or.kr), the identity-theft prevention service run by the Korea Communications Commission and the Korea Association for ICT Promotion (KAIT), sends an alert when a mobile line or similar service is opened in your name, and lets you block new mobile subscriptions in your name altogether. Since identity-document images were not part of this breach it isn't mandatory, but if you are worried, registering as a person whose personal information was exposed on the Financial Supervisory Service's FINE portal (fine.fss.or.kr) is another option (it can make identity checks on your own financial transactions stricter).

5

If you already tapped a link or installed an app

MSIT's notice says that if you installed an app from a link, scan the phone with a mobile antivirus app; if a malicious app is found, switch to airplane mode and report to the police (112) from someone else's phone. Check your mobile micropayment history with your carrier, and sign up for the carrier's free number-theft SMS blocking service so your number isn't used to send more smishing. For general phone hygiene, see smartphone security basics.

Apply for compensation only inside the logged-in official app

TVING is accepting compensation applications from affected members. According to media reports, you log in and use the compensation page in the "MY" menu to check eligibility and apply, and the application period was extended to October 30, 2026. Dates and options can change, so check the notices in the TVING app directly. Treat any "compensation link" arriving by text or messenger as unrelated to this process.

What happened (per MSIT's investigation)

The following is taken from MSIT's June 3 announcement launching the investigation and its September 3 investigation results.

  1. May 30, 2026

    A TVING database server was overloaded by excessive workload. While analyzing the anomaly, TVING recognized that an unauthorized party had accessed internal servers and queried user data.
  2. June 1

    TVING reported the incident to KISA. MSIT and KISA requested preservation of evidence.
  3. June 2

    MSIT and KISA began an on-site investigation.
  4. June 3

    After review by the incident investigation committee, a joint public-private investigation team was formed, and a public smishing warning was issued. From this day TVING ran a dedicated call center for affected users and announced the breach on its website and app.
  5. September 3

    MSIT published the investigation results: 39.54 million accounts (including duplicates) and 361 development projects leaked. The person-level count is to be announced by the Personal Information Protection Commission.
39.54M
Accounts leaked (active, dormant, withdrawn, test; incl. duplicates)
19.04M
Accounts with a CI (13.24M after de-duplication)
20 items
Item types leaked (70 fields; varies by account)
Not decryptable
Passwords (one-way encrypted)
What leaked (MSIT, September 3)
Accounts
22,063,021 active, 8,502,679 dormant, 8,868,174 withdrawn, 106,823 test. 39,540,697 in total, including duplicates. One person held up to 13 accounts
Items
ID, password (one-way encrypted), CJ ONE integrated ID, name, mobile number (last 4 digits encrypted), email address (local part encrypted), date of birth, gender, connecting information (CI), duplicate-registration information (DI), profile name, profile lock PIN (encrypted), refund account number (encrypted), IP address, app-store transaction data, partner-service data, refund amounts and history, TVING coupons, cash balance and payments, payment history
Encryption in practice
Mobile numbers and email addresses were partly encrypted, but the encryption key leaked too, so they were judged equivalent to plain-text leaks
Passwords
One-way encrypted; confirmed impossible to decrypt to plain text
By account type
Accounts with a CI lost 11.1 items on average; accounts without a CI 4.6
Secondary harm
As of the announcement, no user harm had been confirmed and no trading on the dark web had been detected. The team judged that smishing, voice phishing and other secondary harm are possible
Technical assets
Development projects containing source code: 361 projects (30.35 GB) leaked

Why a "compensation" text is the biggest risk

Replaceable

  • Password (not decryptable this time; just end reuse)
  • Email address (a hassle, but changeable)
  • Refund bank account (leaked encrypted; ask your bank if worried)

Not replaceable by you

  • Name, date of birth, gender
  • Connecting information (CI) and DI
  • Mobile number (changeable, but tied to everything)

MSIT describes CI as a unique value that identifies an individual in place of the resident registration number. Unlike a password, it can't be reissued because it leaked. A text from someone who knows your name, date of birth, phone number and the fact that you were a TVING member is far easier to believe than generic spam from an unknown number.

One more condition makes it worse. TVING really is offering compensation, so to a member, "please apply for your compensation" looks like the message they were waiting for. The best moment for a scammer is the period when the real process and the fake message use the same words. That is why this site recommends a simpler rule than "don't tap if it looks suspicious": ignore every compensation-related message and open the app yourself to check. A rule that requires no judgment in the moment is the one people keep following.

For developers and operators: how far one key reached

The investigation team broke the breach into five stages. The figure below reorganizes that path around where it could have been stopped.

1. One developer's dev-environment key

How it was stolen: not confirmed

↓

Device / network restrictions, MFA

2. All 361 development projects

Every developer could access every project

↓

Access only to your team's repos (least privilege)

3. 43 production keys inside the code

41 hard-coded, 3 in plain-text env config (1 duplicate)

↓

Pre-commit secret scanning, keys in a secrets store

4. Cloud production → plain-text DB credentials

↓

Narrow each key's permissions, protect DB credentials

5. Bulk export of the user database

No detection beyond a CPU-load alert

↓

Alerts on bulk reads and outbound volume

The leak path as published by the investigation team (left) and the control that limits damage at each stage (right). Stopping it at any single stage keeps it away from the user database.

The core of the findings is the blast radius of a single key. The investigation team said TVING gave every developer access to every development project, so one dev-environment key reached all 361 projects, and that source code contained production-environment keys. The team also found that anomaly detection relied on simple monitoring such as CPU load, that a hard-coded-key finding from a 2024 penetration test had not been fixed, and that VPN access logs were kept for only about six days. MSIT said it plans to impose an administrative fine under the Network Act because TVING reported the incident more than 24 hours after becoming aware of it.

1

Sweep every repository for secrets — once, this week

The team named "hard-coded in source" and "stored in plain text in environment config" as the problems. First, scan your current repositories and their full commit history with a secret-detection tool, and revoke and reissue anything it finds rather than just deleting it (a key left in history still works after you delete the file). Then add something that blocks secrets before they are committed; see catching secrets before commit with gitleaks.

2

Limit what a developer's key can reach to their team's repositories

Giving everyone access to every repository is convenient, but one leaked key then exposes everything. Split repository access by team, and restrict repositories that handle production keys to an even smaller group. The permission models of self-hosted Git and GitHub are compared in self-hosted Git vs GitHub security.

3

Build one 'outbound volume' alert, not another CPU alert

Per the investigation, the first exfiltration attempt was caught by a database CPU-spike alert, but that alert did not fire during the second, large-scale leak. Load metrics find performance problems, not data theft. Make your first alert "a database account read far more rows at once than usual" or "a newly created server or new key sent large amounts of data out". Alerting on resource-creation events in your cloud audit log is a good place to start.

This site's view: preventable without knowing how the key was stolen

The investigation team could not determine how the dev-environment key was stolen. Incident analysis tends to fixate on "how did they get in", but the lesson here sits on the other side: the team judged that with proper key management the attacker would not have reached the production environment. In other words, even without knowing the entry point, reducing how many doors one key opens reduces the damage. In Japan the same year, most disclosed breaches also came through legitimate credentials rather than software vulnerabilities (2026 breaches ran on legitimate credentials). A Japanese case where a GitHub credential led into a company cloud is covered in the CAMPFIRE breach.

Sources (public record)

The facts in this article are based on the public sources below. We do not speculate about undisclosed methods or causes.

  • Ministry of Science and ICT press release, "TVING breach investigation results" (September 3, 2026; Korean) — msit.go.kr
  • Ministry of Science and ICT press release, "MSIT launches investigation into TVING breach" (June 3, 2026; with annex: public security notice on preventing secondary harm; Korean) — msit.go.kr
  • Report on TVING's June 3 notice — Byline Network (Korean)
  • Report of about 19.53 million people, based on material submitted to the National Assembly in June — Asia Economy
  • Report on the extended compensation period (September 29, 2026) — Nocut News (Korean)
  • Identity-theft prevention — M-Safer (msafer.or.kr) / Financial Supervisory Service — FINE (fine.fss.or.kr) / KISA — Boho Nara (boho.or.kr)

Update history

2026-09-30: First published, based on MSIT's June 3 announcement launching the investigation and its September 3 investigation results. We will update when the Personal Information Protection Commission announces the person-level figure.

FAQ

QWhat was leaked in the TVING breach?
A

According to the Ministry of Science and ICT's September 3, 2026 announcement, 20 item types (70 fields): ID, password (one-way encrypted), CJ ONE integrated ID, name, mobile number, email address, date of birth, gender, connecting information (CI), duplicate-registration information (DI), profile name, profile lock PIN (encrypted), refund account number (encrypted), IP address, and payment, refund, coupon and cash history. What leaked differs by account: accounts that had gone through identity verification (with a CI) lost 11.1 items on average, those without a CI 4.6 items.

QHow many people were affected?
A

The ministry counted accounts, not people: about 22.06 million active, 8.5 million dormant, 8.87 million withdrawn and 0.11 million test accounts, 39.54 million in total including duplicates. One person was found to hold up to 13 accounts. The person-level figure is to be announced by the Personal Information Protection Commission after detailed analysis. In June, a figure of about 19.53 million people was reported.

QI used TVING from outside Korea. Does this affect me?
A

The breach concerns TVING accounts, including those created through CJ ONE or social logins. If you ever had one, even a withdrawn one, assume you may be included. Change any reused password and ignore any message, in any language, that offers TVING compensation or refunds through a link.

QShould I change my TVING password?
A

The investigation team confirmed that passwords were leaked in one-way encrypted form and cannot be decrypted to plain text. Even so, if you used the same password anywhere else, change it there now. Changing your TVING password as well costs nothing.

QWhat are CI and DI?
A

According to the ministry, connecting information (CI) is a unique value that identifies an individual in place of the resident registration number, generated during identity verification for paid services or adult verification. DI is used to check for duplicate registrations. Neither can be changed by the user, so combined with a name, date of birth and phone number they can make impersonation attempts more convincing.

QWhat caused the breach?
A

The investigation team said the attacker stole a TVING developer's development-environment access key, entered the development environment, then used production-environment access keys contained in the source code to get into the cloud production environment and exfiltrate data. How the development-environment key was stolen could not be confirmed despite analysis of multiple scenarios.