TVING
Incident posture
Timeline
Summary
TVING experienced a data breach that exposed approximately 39.54 million accounts, a figure that includes multiple accounts held by the same users. A government investigation identified the incident, prompting the company’s CEO to announce enhanced cybersecurity safeguards and compensation for affected customers. The CEO addressed the issue at a press conference, outlining steps to improve security and provide redress.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In June 2026, a cyberattack targeted the streaming service TVING. A subsequent government investigation determined that the breach compromised approximately 39.54 million accounts. The figure includes multiple accounts held by the same individual users, so the number of distinct affected persons is lower. The investigation was conducted after the incident was detected, though the article does not specify the exact detection method.
Following the investigation's findings, TVING CEO Choi Joo-hee held a press conference in Seoul on September 3, 2026. At the conference she announced that the company would implement strengthened cybersecurity measures to prevent future incidents. She also stated that TVING would provide compensation to affected customers as part of its response to the breach.
The TVING incident occurred amid a series of notable data breaches affecting other South Korean private sector companies. Earlier in November 2025, Coupang disclosed that information tied to 33.7 million customer accounts had been exposed. Two months prior, Lotte Card reported a breach affecting 2.97 million customers. KT disclosed a network intrusion involving about 20,000 subscribers and unauthorized mobile payments. These events contributed to a heightened focus on cybersecurity across both public and private sectors in South Korea.
Sources
Sources available to members: 1 source.