South Korea's Ministry of Science and ICT announced on Thursday (3rd) the findings of an investigation revealing a large-scale hacker intrusion and data leak at the video streaming (OTT) platform Tving. After a three-month joint government-industry investigation, it was confirmed that up to 39.54 million user accounts (including duplicates) and 361 core technical projects—including source code for recommendation and search algorithms, membership management, and payment systems—totaling approximately 30.35 GB—were stolen.
The investigation team identified extremely lax key management as the root cause. Hackers first stole a developer's access key to the 'development environment,' allowing them to enter the system. They downloaded core source code and extracted hardcoded, unencrypted 'production environment' keys embedded within. Even more critically, user database credentials within the production environment were stored in plaintext, enabling unrestricted access.
Lim Jeong-gyu, Director of the Information Security and Network Policy Bureau at the Ministry, stated during a briefing that while the attackers' identities remain unconfirmed, evidence shows the stolen data was transferred to overseas accounts. Police will continue investigations to identify the country from which the attack originated.
Hackers first attempted data exfiltration on May 30, causing server CPU usage to spike to 100%, triggering an alert and prompting Tving to block the intrusion. However, the attackers returned the next day, limiting CPU usage to under 10% to evade detection, using virtual servers as relay points, successfully exfiltrating data before deleting the servers.
The leaked personal data includes names, birthdates, phone numbers, emails, and up to 19.04 million 'connection information (CI)' records. Hackers could analyze the source code to identify further vulnerabilities for future attacks or exploit personal data for SMS and voice phishing scams.
The incident exposes severe security lapses within Tving. Among 265 employees (including 149 developers), only four are dedicated security personnel. Furthermore, the company had identified the hardcoded key vulnerability during an internal simulated hacking test in 2024 but failed to implement any corrective measures.
FACT BOX
- Source: PR Times
- Category: News
- Organizations: CJ ENM
- Products / services: Tving