TVING streaming platform breach exposes nearly 40 million accounts
South Korean streaming service TVING disclosed that an unauthorized party accessed member data; a later government investigation found that a stolen developer access key had exposed 39.54 million accounts and 361 technical assets including source code.
- Victim
- TVING (CJ ENM)
- users
- 39.5M
On 3 June 2026, TVING, the South Korean video streaming platform owned by CJ ENM, publicly apologized after confirming that member personal information had been leaked to an unauthorized external party. The company said exposed fields included user IDs, names, dates of birth, gender, mobile phone numbers and email addresses, and that resident registration numbers and payment details were not involved. It urged users to change their passwords on any other service where they reused their TVING credentials.
TVING did not give a victim count at the time. Three months later, a joint investigation by the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) put the scale at 39.54 million accounts: about 7.26 million direct TVING accounts, 8.63 million CJ ONE integrated memberships and 22.47 million social-login accounts, of which roughly 22 million were active. Investigators also found that 361 technical assets, including source code, had been taken.
How it happened
According to the investigation, an unidentified attacker stole a developer's access key and used it to enter TVING's internal systems. The exposed data spanned some 70 types of information across 20 categories, including connection details. No group has publicly claimed the intrusion, and police are investigating.
TVING detected the breach on 30 May 2026 but reported it to KISA only on 1 June, missing the 24-hour notification requirement. The Personal Information Protection Commission is reviewing penalties for both the reporting delay and the breach itself.
Why it matters
With nearly 40 million accounts affected, the TVING incident is one of the largest South Korean data breaches of 2026, following other high-profile consumer breaches in the country. It shows how a single leaked developer credential can open both customer data and source code, and investigators warned that the stolen data could fuel follow-on smishing and voice-phishing campaigns against Korean users.
Timeline
TVING detects the intrusion into its internal systems.
TVING reports the incident to the Korea Internet & Security Agency (KISA), later than the 24-hour deadline.
TVING publicly apologizes and confirms that member personal information was leaked to an unauthorized external party.
A joint government investigation finds that 39.54 million accounts and 361 technical assets, including source code, were compromised.
Sources
- koreajoongangdaily.comhttps://www.koreajoongangdaily.com/business/streaming-service-tving-confirms-third-party-user-data-leak/12599766
- en.sedaily.comhttps://en.sedaily.com/technology/2026/06/03/tving-suffers-data-breach-member-personal-information-leaked
- koreaherald.comhttps://www.koreaherald.com/article/10861814
- koreatimes.co.krhttps://www.koreatimes.co.kr/business/companies/20260903/nearly-40-mil-tving-accounts-compromised-in-massive-data-breach-probe