South Korea
2 articles with this tag
A real compensation program makes fake compensation texts believable — what TVING users should do after the breach
According to the investigation results published on September 3, 2026 by South Korea's Ministry of Science and ICT and its joint public-private investigation team, the TVING breach exposed data on 39.54 million accounts (active, dormant, withdrawn and test accounts, including duplicates). The 20 leaked item types (70 fields) include ID, name, date of birth, connecting information (CI), duplicate-registration information (DI), refund account numbers (encrypted) and passwords (one-way encrypted); passwords were confirmed to be impossible to decrypt. This site's take: because TVING is genuinely running a compensation program, fake 'compensation' and 'refund' texts are the most convincing lure right now. Check compensation only inside the official app you open yourself, change passwords wherever you reused them, and turn on identity-theft alerts if you live in Korea. For developers, the lesson is structural: one developer key led to all source code, and the source code held production keys.
Charging history wasn't on the list, but every record had an email — what CHAEVI users should do after the breach
According to CHAEVI's notices of July 26 and July 30, 2026, an illegal external hacking attack on July 23 leaked a total of 298,333 personal data records: 164,858 email-only, 131,411 email plus password (encrypted), 1,235 email plus name and contact number (encrypted), gender, date of birth and more, and 829 with all of that plus the password (encrypted). CHAEVI says it does not collect or hold resident registration numbers, passport numbers, or card and account numbers, so none were leaked, and that while investigating it also found a separate leak from around January 2025, which is still under investigation. Charging history and location do not appear in the notices' list of leaked items. This site's take: the most usable material in this breach is what every affected record shares — a plaintext email address — combined with the fact that its owner uses an EV-charging app. Ignore emails and texts about charging fees, unpaid balances or compensation by default, and change your password starting with every other service where you reused it.