When the Tving personal data leak incident first came to light last June, I remember immediately accessing the official website to check my leak history and posting about defense measures. However, looking at the final results from the Ministry of Science and ICT’s joint public-private investigation team, that initial unease was just a trailer. The final confirmed scale of leaked accounts reaches approximately 39.54 million.
A notable point in this announcement is that the proportion of inactive or already withdrawn accounts is significantly higher than active users currently using the service. About 17.37 million of the total leaked list turned out to be dormant and withdrawn accounts. This means data from users who left the service a long time ago remained intact somewhere on the servers before leaking externally.
This leaves fundamental doubts about whether the basic procedure of destroying data after service termination actually worked properly.
Notice of Apology and Compensation for Cyber Security Incident (Date: September 3, 2026)
Compensation Target
• Target Members: Members notified as incident targets
• How to Check: Check target member status in MY Menu > Compensation Application Page
Compensation Schedule and Application Method
• Application Schedule: September 7, 2026 (Mon) 10:00 ~ September 30, 2026 (Wed) 23:59
• Compensation Schedule: Sequential compensation starting October 6, 2026 (Tue) 10:00 (Refer to Section 3. Compensation Details for usage periods per item)
• Application Method:
① Log in to Tving website or mobile APP
② Go to MY Menu > Compensation Application Page
③ Proceed with identity verification
④ Select and apply for compensation
※ Compensation applications must be made directly after logging into Tving and undergoing identity verification.
(We ask for your understanding that applications via customer service are not supported.)
Inquiries
• Dedicated Customer Center: ☎ 1551-2391
• Operating Hours: Weekdays/Weekends 09:00 ~ 18:00 (Closed on holidays)
✓ Please Check
• Applications cannot be made after the deadline (September 30, 2026, 23:59), so please apply within the period.
• Compensation not used within the usage period will automatically expire, and period extensions are not possible.
• Compensation can only be applied for once, and selected items cannot be changed after application.
The Truth Behind the 3 Million Won Compensation Figure
The part that has caused the most controversy and misunderstanding is undoubtedly the compensation plan. The title “up to 3 million won compensation” is highlighted everywhere, but this is not cash deposited directly into victims’ accounts. It is merely the maximum limit that can be received after passing a strict review of terms if actual financial damage such as financial fraud occurs after being enrolled for one year in a hacking and phishing insurance policy prepared by the company.
The perceived value of compensation per person calculated by Tving itself is around 20,000 won. It is structured to choose one of 5,000 points used for paid content internally, a 1-month Wavve pass, or a 5,000 won theater combo discount coupon. Currently, an additional benefit of upgrading the viewing environment until the end of the year has been added for paid subscribers.
Considering the heavy value of lost personal information, countermeasures centered on points and in-house coupons feel rather shabby. Moreover, members who have already left Tving and withdrawn are designed to receive these coupons only if they sign up for the service again, leaving much to be desired.
The Real Detonator Is Not IDs or Passwords
The most painful blow in this leak incident lies elsewhere.
It is the exposure of CI (Connecting Information).
CI is a unique cryptographic value used for personal authentication in online environments, acting like a digital fingerprint that follows you for life unless offline resident registration numbers are completely changed. Fortunately, the leaked passwords themselves were unidirectionally encrypted so the original text could not be found, but emails and mobile phone numbers had the keys to unlock them leaked entirely, leaving them exposed practically in plain text.
The fact that an unchangeable CI value and a phone number currently in hand were leaked externally together is a very serious problem. When combined with other leaked information on the dark web, advanced targeted crimes that accurately pinpoint your name, workplace, and family relationships are likely to run rampant in the future.
Examining the cause of this incident reveals the bitter naked face of internal system management.
- Access keys entering the actual user DB were stored in source code in plain text without separate measures
- Out of 265 total executives and employees, only about 4 people are dedicated to information security
- Already aware of the fatal vulnerability of access key exposure during self-mock hacking training in 2024
Practical Guide to Protecting Your Identity Right Now
Tving’s point or coupon application period is set from September 7 to September 30. However, as emphasized in the June post, a much more urgent task than grabbing those perks is building your fences solidly again right now.
First, I recommend directly accessing the inquiry page prepared on the official website to check again specifically which items leaked from your account and capture that screen. It serves as minimal physical evidence to prove company negligence when financial damage occurs or you participate in a lawsuit later.
Also, if you have portal sites, major emails, or financial apps using the same ID and password combination as Tving, you must change them to a completely different pattern right now. If you have no plans to open a new phone or take out a loan, accessing the M-Safer website to block carrier sign-ups and registering as a personal information leakage victim on the Financial Consumer Portal Fine also serve as solid defenses against identity theft.
Recovering from the Incident
Although a belated announcement was made to quadruple the information security budget and triple the workforce, we still have a long way to go to regain lost trust. For the time being, ignoring and avoiding links in text messages mentioning consolation money or refund applications will be the top defense strategy.
📸 Behind the scenes
Check out more behind-the-scenes shots on my Naver blog (Korean):
티빙 유출 보상 규모와 신청방법. 300만원 보상은 착시, 진짜 큰일은
👉 https://blog.naver.com/PostView.naver?blogId=k5kun&logNo=224402733924