Tving confirmed that 39.54 million account records were leaked in a security breach. Tving logo. [Photo: Tving]

[Digital Today reporter Jin-ho Lee (이진호)] Tving has confirmed that 39.54 million account records were leaked in a security breach. Investigators found the attacker stole a developer access key, penetrated the internal development environment and then moved into the production environment to carry out a large-scale leak.

The Ministry of Science and ICT announced on Wednesday the results of a joint public-private investigation team, formed with the Korea Internet & Security Agency (KISA), into the Tving breach.

After confirming abnormal access to Tving's user information database (DB), the team examined how the developer access key was stolen, the intrusion path, the scale of the leak and the companywide information security management system.

◆ 22.06 million login-enabled accounts included; accounts with CI suffer bigger leak

The investigation team said the leaked accounts totalled 39.54 million, including 22.06 million active accounts that can currently log in, 17.37 million inactive accounts such as dormant or withdrawn users, and 110,000 test accounts.

The 39.54 million accounts differ from the number of actual users. Tving allows sign-ups through multiple channels such as direct registration, CJ ONE integrated membership and social media (SNS) simple sign-up, so duplicate accounts for the same user were included. During the investigation, one case was confirmed in which a single person held up to 13 accounts.

The leaked data covered 70 types across 20 items, including IDs and passwords, names, mobile phone numbers, email addresses, dates of birth, linked information (CI) and payment history. CI is a unique value used to identify the same user in place of a resident registration number. It is generated and collected during identity verification processes such as paid payments or adult verification.

The actual leaked information differed depending on account characteristics. There were 19.04 million accounts with CI, or 13.24 million after removing duplicates, with an average of 11.1 items leaked per account. Among 20.40 million accounts without CI, an average of 4.6 items were leaked. The Personal Information Protection Commission plans to confirm the detailed scale of the personal data leak after additional analysis.

Passwords were leaked in a one-way encrypted form, making plaintext decryption impossible, investigators confirmed. Mobile phone numbers and email addresses were partially encrypted, but the encryption keys were leaked together, so the investigation team judged it to be equivalent to a plaintext leak.

Technical assets were also leaked. The attacker took 361 development projects containing source code, about 30.35GB. They included technology related to personalised content recommendation and search algorithms, user management and authentication systems, payment management and the operation of paid services.

There have been no cases so far of user harm from the misuse of the leaked information. The ministry said, "No user damage cases have been confirmed so far," adding, "No signs of illegal trading or distribution through the dark web have been detected."

◆ Theft of developer access key triggered attack; operational key in source code used to enter system

The hack was triggered by the theft of a developer-held access key. The team divided the leak path into five stages: intrusion into the development environment; access to the production environment and theft of a 'production environment access key' with administrative privileges; intrusion into the production environment; a first attempt to leak; and a second leak attempt and large-scale data exfiltration.

The attacker stole the development environment access key in advance and accessed Tving's development environment without authorisation on May 29. The attacker then began extracting accessible development projects. In the first attack, 14 projects were leaked, and in the second attack all 361 development projects were leaked.

To determine how the initial access key was stolen, the team conducted forensic analysis of 9 developer devices and reviewed the possibility of phishing, malware, supply chain attacks, sharing or misuse of access keys, and vulnerability exploitation. But it could not confirm the route by which the initial development environment access key was stolen due to poor key management and limits on the log retention period.

The leaked development projects became the key for the hacker to penetrate Tving's system. The leaked projects contained another access key that could access the production environment. The 361 development projects included 43 production environment access keys. Of these, 41 were hard-coded by being entered directly into source code. Some were stored in plaintext without separate encryption.

The attacker used 2 of the 43 access keys in the actual attack. The attacker then penetrated Tving's production environment and found that the IDs and passwords that could access the user information DB were not encrypted, and stole them.

On May 30, the attacker used the acquired access information to attempt a first data leak. During the process, the DB server's central processing unit (CPU) usage surged to 100 percent, triggering an anomaly alert, and Tving blocked the activity.

The next day, the attacker created a new virtual server and used it as a channel to exfiltrate about 24GB of user information to an external server. The attacker then deleted the virtual server to erase traces. Unlike the first attack, there was no excessive workload alert on the DB server in this process. The team judged that the attacker limited CPU usage, given that CPU usage stayed within 10 percent during the second attack.

◆ All developers could access all projects; vulnerabilities found in penetration test left unaddressed

Problems were also found across Tving's information security management system. Tving developers hard-coded development and production environment access keys into source code or stored them in plaintext. Some access keys were also shared with others through internal messengers.

In particular, all developers were granted permission to access all development projects. This meant the structure allowed access to all projects if just one development environment access key was stolen. Procedures to manage the issuance, use, change, disposal and regular inspection of access keys were also found to be inadequate.

The security monitoring system was also insufficient. Tving relied on simple indicators such as CPU load and failed to detect and block abnormal network or data activities in real time. The probe found no access control policies such as allowing access only from authorised internet protocol (IP) addresses or applying multi-factor authentication (MFA).

A shortage of information security staff was also identified. Tving had 265 employees in total, including 149 developers, but had about 4 dedicated information security staff excluding outsourced workers. The team judged that staffing at that level had limits in carrying out round-the-clock security monitoring, vulnerability checks and abnormal activity monitoring.

Penetration testing also failed to prevent the incident. Tving had already found through a 2024 penetration test a vulnerability in which development and production environment access keys were hard-coded in source code, but did not improve it. Log management was also insufficient, including keeping connection records for new virtual private network (VPN) equipment for only about 6 days. Regular security checks, such as installing and updating antivirus software on work PCs, were also not carried out sufficiently.

◆ Delayed reporting of the situation; reported after more than 24 hours despite recognising the incident

Problems were also identified in the response process. An anomaly first appeared at 6 p.m. on May 30, but the situation was not relayed to the dedicated information security organisation overseeing incident response and the chief information security officer (CISO) until about 14 hours later.

The team judged that Tving recognised the incident at 10:10 a.m. on May 31, when it shared with the information security team suspicions of production environment access key theft and data leakage. Under the current Information and Communications Network Act, companies must report to the ministry or KISA within 24 hours of recognising an incident.

But Tving reported to KISA at 3:08 p.m. on June 1, the next day. The ministry plans to impose an administrative fine of up to 30 million won under the Information and Communications Network Act for the delayed report.

The team instructed Tving to build a key management, control and access authority system and to clarify operational management standards. It also told the company to establish a log storage management policy and a key history management system and to carry out ongoing inspections. Tving must also improve access control policies, including detecting abnormal behaviour and strengthening monitoring for large-volume data queries. The team also urged it to secure sufficient dedicated information security staff and budget.

The ministry will require Tving to submit an implementation plan for measures to prevent recurrence within this month and will check implementation from October to December. From January next year, it plans to conduct implementation inspections and order corrective measures for items that need supplementation.

Keyword

#Tving #Ministry of Science and ICT #KISA #CJ ONE #CISO
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.