TVING Chief Executive Choi Ju-hee apologises on Sept. 3 at a briefing on a cyber incident at the Koreana Hotel in Seoul. [Photo: DigitalToday]

TVING, after the leak of personal data from about 39.54 million accounts, will provide affected users with a compensation package including 5,000 won worth of TVING points, viewing-environment upgrades and insurance. TVING described the overall package as having a perceived value of about 20,000 won per person, but it is not a cash payout. Former users who have withdrawn must rejoin to receive compensation, raising expectations of debate over its effectiveness.

Choi Ju-hee (최주희), TVING's chief executive, said at a "cyber incident briefing" held on Sept. 3 at the Koreana Hotel in central Seoul that she sincerely apologised for causing customers serious concern and anxiety. She said she felt a heavy responsibility as chief executive.

She added that the company would rebuild its information security system from the ground up. She said it would make information protection its most important responsibility and a competitive edge, and do its utmost to restore customer trust.

TVING announced compensation measures for affected users consisting of insurance against hacking and phishing, a premium-grade viewing-environment upgrade, 5,000 won worth of TVING points, and entertainment coupons.

The insurance will be provided for 1 year. It covers up to 3 million won per person for cyber financial fraud from hacking and phishing, as well as fraud on online shopping malls and person-to-person direct transactions.

For customers currently subscribing to a TVING pass, a premium-grade viewing environment will be applied for 3 months from October to December without a separate application. Customers already using a premium pass will receive an additional 5,000 won worth of TVING points.

Affected users will also receive 5,000 won worth of TVING points that can be used for individually purchased content such as the latest films. They will also receive an entertainment coupon that allows them to choose either a 1-month Wavve AVOD pass or a CGV combo discount coupon.

Jang Hyun-kyung (장현경), head of TVING's business management division, explained the package by saying its perceived value was about 20,000 won per person.

The company avoided giving a specific answer on the scale of the financial burden from the compensation plan. TVING said it is internally estimating the related costs, but did not disclose a total because costs could vary depending on the actual number of eligible recipients, the application rate and the items users choose.

Earlier, the Ministry of Science and ICT announced the results of a joint public-private investigation team, saying information from a total of 39.54 million accounts was leaked. The figure included 22.06 million active accounts, 8.5 million dormant accounts, 8.87 million withdrawn accounts and 110,000 test accounts. The ministry said the number includes duplicate accounts, and the actual number of people affected will be confirmed after additional investigation by the Personal Information Protection Commission.

Debate is also expected over the effectiveness of the compensation method. TVING included dormant and withdrawn users among those eligible, but users who have already withdrawn must rejoin to receive compensation.

Choi said a subscription is not necessary, but signing up is required to match information and values the company holds. TVING also said again that withdrawn users must rejoin and log in to receive compensation.

The application period is also limited to 24 days, from Sept. 7 to 30. TVING said users must apply through a separate page during that period to receive compensation. It did not present a specific additional remedy on Sept. 3 for users who miss the deadline.

Security investment to quadruple... Explaining controversy over neglected vulnerabilities and security staffing

TVING will also overhaul its information protection system separately from compensation. It plans to increase its information protection investment, currently about 3 billion won this year, to an annual 10 billion to 12 billion won in 5 years. It will expand its internal information protection staff from about 4 now to 10 by the end of this year, and to 15 to 16 including outsourced staff. Over the next 5 years, it aims to secure 25 to 30 people in total, including internal and external personnel.

TVING also provided additional explanations on some issues pointed out by the joint investigation team. The team said TVING found a vulnerability in a 2024 mock hacking exercise in which development and operations access keys were exposed as-is in source code, but did not fix it.

In response, TVING Network Technology Division head Cho Seong-dae (조성대) said the project identified in the 2024 mock hacking exercise and the project exploited in this incident were not the same. He added that the company took over a project that used access keys during service changes, and the attack occurred while related changes were under way.

TVING also said a difference in calculation standards explained why the investigation team estimated dedicated information protection staff at about 4, while TVING's information protection disclosure listed related staff at 9.4 last year. TVING said the 4 counted by the investigation team covered only internal dedicated staff, and that including about 5 to 6 outsourced staff, the actual number of people assigned to security work is about 10.

On the difference over the time it became aware of the incident, TVING acknowledged that its internal reporting system was inadequate. The investigation team judged the awareness time as 10:10 a.m. on May 31, when a suspected incident was shared with the information security team, but TVING reported 3:09 p.m. that day, when it was reported to management and a joint response system was activated.

Choi said the system for quickly sharing issues internally and enabling everyone to respond together was institutionally inadequate.

The responsibility issue over poor security management has not been fully resolved. The investigation team judged that key management was broadly inadequate, including granting all developers access to all development projects and storing access keys in plain text or sharing them through an internal messenger.

A total of 361 development projects were also leaked, including source code needed for TVING service operations and development as well as user information. TVING said it completed a comprehensive vulnerability inspection through a private security company and is now conducting AI-based vulnerability analysis and work to improve and change existing code.

No specific personnel actions related to management responsibility were disclosed on Sept. 3. Choi said on legal liability for damages that the company would fulfill its responsibilities as determined under relevant laws.

Keyword

#TVING #Ministry of Science and ICT #Personal Information Protection Commission #Wavve #CGV
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.