TVING
South Korea's leading streaming platform confirms user data leaked including passwords and refund account numbers. Scope still under investigation.
What happened?
On June 3, 2026, TVING—a South Korean video streaming service owned by CJ ENM—confirmed that user personal information had been leaked due to unauthorized external access. TVING operates as a subscription video-on-demand and over-the-top streaming platform with millions of users across South Korea and increasingly in global markets.
The company disclosed that the breach was identified through security monitoring but has not yet determined the full scope of affected users. The total number of compromised records remains under investigation.
What data was actually inside?
User IDs and passwords. Names. Birthdates. Phone numbers. Email addresses. Refund account numbers. This is a comprehensive user profile—authentication credentials plus identity information plus financial data.
The inclusion of passwords (even if hashed) creates immediate credential stuffing risk. The refund account numbers—likely bank accounts linked for subscription cancellation refunds—add a direct financial exposure layer. Users who reuse passwords across services are at particular risk.
Who gets hurt and how?
Every TVING user whose credentials were stored. Korean streaming subscribers who may have linked their accounts to Korean Resident Registration Numbers (the Korean equivalent of Social Security numbers) for age verification. Anyone who reused their TVING password on other services.
Birthdates and phone numbers combined with names enable identity verification bypass at other services. The refund account exposure means attackers know where affected users bank. This combination supports both credential stuffing across platforms and targeted social engineering against specific individuals.
What did they think they were doing right?
TVING is a major platform backed by CJ ENM, one of South Korea's largest media conglomerates. Enterprise-scale streaming platforms invest heavily in availability, performance, and content protection. The business priorities are uptime and preventing content piracy.
But content protection and user data protection are different security domains. DRM systems that prevent movie piracy don't protect user account databases. The security controls optimized for protecting streaming content aren't the same controls that protect user credentials and financial information.
What did they not know about their own data?
The scope remains under investigation. This typically means the company cannot yet determine which users were affected or how much data was accessed. User databases grow over time—accounts from years of subscriber acquisition, inactive accounts, trial accounts, users who canceled but whose data persists.
Refund account numbers suggest financial data was stored longer than necessary for active transactions. If a user received a refund three years ago, do those bank details still need to be retained? The breach scope expands with every category of data that was kept beyond its operational necessity.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
South Korea's Personal Information Protection Act (PIPA) requires breach notification to affected individuals and the Personal Information Protection Commission. The timeline is tight—companies must notify within 72 hours of discovering a breach affecting 1,000+ people.
PIPA also imposes substantial penalties—up to 4% of annual revenue for serious violations. CJ ENM, as the parent company of TVING, faces both regulatory scrutiny and reputational risk in a market where data privacy is increasingly important to consumers. The "under investigation" status extends that uncertainty.
What would have changed the outcome?
Knowing exactly what user data was stored, where it resided, and implementing retention policies that limited historical exposure.
Streaming platforms accumulate user data across years of subscriptions. Old accounts, historical payment methods, trial registrations that never converted. When attackers breach a user database, they get everything that exists—not just what should exist. Data minimization before the breach determines breach scope after.
TVING found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.