Tving Hacked, Exposing 39.54 Million User Accounts
IT DAILY ·
✦ AI Summary
The government said the investigation into the Tving breach confirmed the leak of 39.54 million user accounts.
The leaked information was identified as 20 items and 70 types, and the accounts were analyzed separately into 19.04 million CI-holding accounts and 20.4 million CI-nonholding accounts.
No user damage cases or signs of illegal trading or distribution of information have been confirmed so far.
The government said that, after investigating the Tving breach, it confirmed that 39.54 million user accounts of Tving, the online video service (OTT) company, were leaked, and that the Ministry of Science and ICT announced the results of the joint public-private investigation team’s probe into the incident on the 3rd. The leak was confirmed through the government investigation, and the scale of damage was found to be all user accounts Tving held at the time of the breach. The leaked information for accounts holding connection information (CI) was found to include an average of 11 items, including mobile phone numbers and email addresses.
The Ministry of Science and ICT held a briefing on the results of the Tving joint public-private investigation team’s probe at the Government Complex Seoul in Jongno-gu, Seoul, on the 3rd, and Lim Jeong-gyu, director of information security and network policy at the ministry, announced the findings. The photo credit reads Kim Ho-jun.
On May 30, Tving confirmed unauthorized access to its server by an outsider while analyzing anomalies caused by excessive workload on a DB server. Tving then reported the incident to the Korea Internet & Security Agency (KISA) on June 1.
The Ministry of Science and ICT and KISA began assessing the situation on June 2, and the ministry formed the joint public-private investigation team on June 3. The team conducted an analysis of Tving's DB and logs.
The analysis confirmed the leak of 39.54 million user accounts. The leaked accounts consisted of 22.06 million active accounts, 17.37 million inactive accounts, and 110,000 test accounts. The inactive accounts comprised 8.5 million dormant accounts and 8.87 million closed accounts. Tving's account structure allows one person to have multiple accounts, so duplicate entries are included in the 39.54 million-account figure.
The breached information was identified as 20 items and 70 types. The leaked items included ID, password (one-way encryption), CJ ONE integrated ID, name, mobile phone number, email address, date of birth, and CI. The detailed scale of the leak is expected to be announced after an in-depth analysis by the Personal Information Protection Commission.
The investigation team determined that even if some leaked items, such as mobile phone numbers and email addresses, were exposed in encrypted form, they can be decrypted because the encryption key was leaked along with them, making them equivalent to plain-text exposure. By contrast, passwords were leaked in one-way encrypted form, and the Ministry of Science and ICT said plain-text password decryption is impossible.
The total of 39.54 million accounts was also analyzed separately according to differences in the scale of leaked information depending on whether CI was held. Lim Jeong-gyu, director of information security and network policy at the Ministry of Science and ICT, said that because the 39.54 million accounts included many duplicates, they were first divided based on whether they held CI, and explained that among 19.04 million CI-holding accounts, 5.8 million accounts were confirmed to be duplicates based on CI, leaving 13.24 million accounts after duplicates were removed. The scale of the leak for CI-holding accounts was an average of 11.1 items and 17.6 types.
Lim Jeong-gyu, director of information security and network policy at the Ministry of Science and ICT, said that the 20.4 million accounts without CI could not yet be checked for duplicates. The scale of the leak for the 20.4 million CI-nonholding accounts was an average of 4.6 items and 5.9 types. He also said that the CI-nonholding accounts had not undergone identity verification procedures and that some data, including names, mobile phone numbers, and email addresses, were missing or inaccurate.
Based on its assessment of the possibility of secondary damage such as smishing and voice phishing, the investigation team has operated a dedicated counseling call center since June 3 and strengthened real-time monitoring to detect illegal trading on the dark web and hacking forums.
According to the ministry's announcement, no user damage cases have been confirmed so far, and there have been no confirmed signs of illegal trading or distribution of information so far. While the possibility of damage from CI leakage is drawing public attention, the Ministry of Science and ICT inquired with the Broadcasting Media and Communications Commission about CI-related issues, and the commission replied that CI is not information used for access like ID and passwords, so the possibility of direct misuse of CI is low. However, the commission added that if CI is combined with other information, an individual can be identified, and combined CI can be exploited for smishing and phishing.
Based on the investigation results, the Ministry of Science and ICT asked Tving to submit an implementation plan for measures to prevent recurrence, and plans to continue monitoring whether Tving follows through.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241387
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.