Attention is focused on the government investigation results into a mass personal data breach at online video service (OTT) Tving. [Photo: Tving]

Attention is focused on the outcome of a government investigation into a mass personal data breach at online video service (OTT) Tving. The known scale of the leak exceeds 19 million people, and the actual number of victims and details of the hacking process are expected to be identified. The incident is also far larger than Tving’s actual user base, putting how account information has been managed at the center of scrutiny.

The industry and the Ministry of Science and ICT said on Sept. 1 that a public-private joint investigation team has wrapped up its probe into the Tving data breach and is expected to announce the results this week.

Tving said on June 3 that user personal information was leaked due to unauthorized external access. The leaked information included IDs, names, dates of birth and gender, as well as connected information (CI), duplicate subscription verification information (DI), mobile phone numbers, email addresses, refund bank account numbers and passwords.

Hacking scale exceeds subscriber base; management of withdrawn, dormant and partner accounts in focus

The government initially put the scale at about 13 million people, but it later rose to 19.53 million during the investigation. Lee Jeong-heon (이정헌), a lawmaker from the Democratic Party, said the leaked items included large amounts of sensitive unique identification information, heightening concerns about secondary harm. He said CI and DI, often called digital resident registration numbers, cannot be changed and carry a very high risk of being abused for financial crimes such as identity theft.

The problem is that 19.53 million differs sharply from the scale of Tving’s service usage. Tving has about 5 million paid subscribers. Monthly active users (MAU) also fall short of 10 million. It is difficult to explain a figure of 19.53 million based only on current users.

The investigation results are expected to first clarify whether 19.53 million is a count of actual individuals or a count based on accounts. It will also be key whether users who held multiple accounts through different sign-up routes were double-counted and how much information on users who withdrew or did not use the service for a long time was included among the leaked data. The scope of damage assessment has grown more complex after it was found that information on customers who used Tving through partner channels, such as simple logins via Naver and Kakao or bundled products with telecom operators, was also included in the leaked data.

How much information on withdrawn members was actually included in the leaked data is an important factor in assessing Tving’s management responsibility. If personal information remained after withdrawal without a legal basis for retention and that information was also leaked, the appropriateness of data retention and disposal processes could become an issue. An industry official said the damage scale should be watched closely because it will also affect how the Personal Information Protection Commission calculates penalties.

How did hackers access the database; attention also on PIPC sanctions

The process by which hackers infiltrated Tving’s system and exfiltrated large amounts of data is also in focus. Tving first detected signs of abnormal activity on May 30, and on June 2 it recognized indications that unauthorized access had been made to a database (DB) storing user personal information and that data had leaked. The government probe is expected to focus on what vulnerabilities or credentials hackers used to enter internal systems and how they then reached the DB containing personal information.

Another point to be checked is whether Tving’s security system detected or blocked mass data queries and external transfers in time. With a gap of several days between when abnormal signs were first detected and when the leak was confirmed, whether internal monitoring and response systems were adequate is also seen as a factor in determining the scope of responsibility.

Even after the joint investigation team announces its findings, the level of sanctions will not be decided immediately. That is because the Personal Information Protection Commission is separately investigating whether Tving violated the Personal Information Protection Act. If violations are confirmed, the commission decides sanctions such as penalty surcharges and fines based on the seriousness of the violations and related sales. The actual breach scale, whether unnecessary personal information was retained and how the incident was handled could affect the decision on sanctions.

The government probe results are also expected to affect Tving’s future civil liability. With moves among users to pursue damages lawsuits after the breach, any findings of specific security negligence or problems in managing personal information could be used as key grounds in related litigation.

Tving is also preparing a separate customer compensation plan. CJ ENM previously said on a second-quarter earnings conference call that it plans to disclose a compensation plan related to the Tving data breach in September to October. Industry sources said Tving is preparing a separate briefing to coincide with the timing of the joint investigation team’s announcement.

An industry official said the investigation results will cover basic details of the hacking incident and that the hacking scale is the core issue. The official said it cannot be ruled out that the OTT industry landscape could be reshaped depending on the level of sanctions.

Keyword

#Tving #Ministry of Science and ICT #Personal Information Protection Commission #CJ ENM #CI
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.