[Dispatch=Yuhaneul Reporter] Online video service (OTT) Tving has apologized for a personal information breach. The company is undertaking a comprehensive overhaul of its security system and launching customer compensation measures.
Tving held an official apology and briefing session regarding the cyber attack on the 3rd at the Koriana Hotel in Jung-gu, Seoul. CEO Choi Ju-hee of Tving and other key executives attended.
CEO Choi said, "I sincerely apologize for causing concern to our customers due to this breach," and added, "I feel heavy responsibility for failing to provide a safe service."
The company accepted the findings of the private-public joint investigation team. CEO Choi stated, "We will implement all necessary corrective measures and recurrence prevention plans for the pointed-out issues to the end."
Tving plans to significantly expand information security investment and personnel by 2030. The scale is planned to be approximately 4 times larger than the previous 5 years. Over the next 5 years, the company will increase information security specialist personnel to 3 times the current level.
The company established Zero-Trust as its basic security principle. The plan is to unify authentication and access control methods into a company-wide security standard system that verifies each step sequentially.
A customer compensation plan has also been prepared. The company will provide peace-of-mind insurance covering fraud damages such as hacking and phishing for one year. Up to 3 million won per person is provided. All customers will be automatically upgraded to a premium viewing environment without separate application.
Tving points worth 5,000 won will also be provided. Customers can choose one of the following: a one-month subscription to Wave's ad-supported plan or a CGV discount coupon. The compensation package can be applied from the 7th to the 30th. It will take effect from the 6th of next month.
CEO Choi stressed, "We will take this matter seriously and rebuild our entire security system from the ground up," adding, "We will make information security the company's most important responsibility and competitiveness, and expand information security investment and personnel."
He further bowed, saying, "Above all, we will do our best to restore customer trust," and "We will create an environment where customers can use our service with peace of mind."
The Ministry of Science and ICT announced the results of the breach investigation at the Government Seoul Building on the same day. The number of user accounts exposed externally was identified as approximately 39.54 million.
According to the private-public joint investigation team's confirmation, a total of 20 items (70 types) of personal information were leaked. These include name, date of birth, gender, phone number, email address, and CI (connecting information).
Passwords were encrypted one-way and were excluded from the leaked data. However, phone numbers and email addresses were leaked along with encryption keys. The investigation team assessed this as equivalent to plaintext exposure in effect.
Tving's internal technical assets were also damaged. 361 development projects including source code were exposed externally. The total size of the leaked data reached 30.35GB.
The attacker reportedly obtained access keys used by developers and accessed internal systems. The Ministry of Science and ICT plans to identify the hacking attacker through police investigation at a later date.
The investigation team pointed out deficiencies in Tving's key management system, absence of monitoring, and lack of dedicated information security personnel. The team determined that the company's enterprise-wide information security management system was inadequate.
The process of reporting the breach was also questioned. Tving discovered the incident on May 31st at 10:10 a.m. However, it reported the breach to the Korea Internet & Security Agency (KISA) on June 1st at around 3 p.m.
This exceeded the statutory reporting deadline of 24 hours. The Ministry of Science and ICT has determined this to be a violation of the Information and Communications Network Act and plans to impose a fine of up to 30 million won on Tving.
<Photo source=Tving>