Tving Data Breach Exposed 39.54 Million Accounts Amid Poor Key Management and Failed Monitoring
IT DAILY ·
✦ AI Summary
The Ministry of Science and ICT said on the 3rd that its investigation into the Tving security incident confirmed the leakage of 39.54 million accounts.
The investigation team found that Tving's system was intruded into twice on May 29 through the theft of a developer access key and the exploitation of access keys for the operations environment that had been hardcoded or stored in plain text.
The Ministry of Science and ICT pointed to poor key management and the absence of a monitoring system, and demanded that Tving submit a plan to implement recurrence-prevention measures and undergo inspections.
Regarding the Tving security incident, the Ministry of Science and ICT on the 3rd announced the findings of a public-private joint investigation team. The team said it confirmed the leak of 39.54 million accounts through analysis of Tving's DB and related logs. It explained that the number of active accounts was 22.06 million, and that the figure included duplicates because the service allows multiple accounts per person. The scope of the leaked information covered 20 items across 70 types, including ID, password (one-way encryption), CJ ONE integrated ID, name, mobile phone number, email address, date of birth, and CI. In addition to customer information, the investigation found that 361 development projects inside Tving's system were also among the leaked data.
The government investigation found that the attacker broke into Tving's system after stealing an access key held by a developer. The attacker was identified as having gained unauthorized access to customer information through that method.
The investigation pointed to poor key management and the absence of a monitoring system as Tving's key problems. It concluded that, as a result, abnormal signs were not detected.
The Ministry of Science and ICT released an overview diagram of the Tving personal information leak incident. Tving discovered overload caused by excessive DB server workload on May 30 and began analyzing abnormal signs. In the process, it confirmed unauthorized internal server access by an outsider and also became aware that user information had been queried.
Tving reported the security incident to the Korea Internet & Security Agency (KISA) on June 1. The Ministry of Science and ICT then formed the public-private joint investigation team on June 3, and the team began investigating the scale of the damage and the cause of the incident.
The investigation found that the attacker stole a developer access key for Tving on May 29. Tving was using a developer collaboration platform for source code storage, simultaneous editing, and management, and each developer held a personal access key for accessing that environment. The attacker used the stolen key to access the development environment without authorization.
The Ministry of Science and ICT investigation also confirmed signs that the intrusion spread from the development environment to the cloud. The attacker penetrated internal systems using the stolen access key, and the chain of access-key theft continued. As a result, the attacker was found to have leaked all 361 projects.
To identify the theft route, the investigation team singled out the developers who had used the access key involved and carried out forensic analysis on 9 devices. It also conducted a detailed analysis by assuming phishing, malware infection, and software supply-chain attacks as scenario-based avenues for tracing the cause.
However, due to limits on log retention periods, the team was unable to secure enough necessary records, and in the end it failed to determine how the attacker obtained the access key. Tving had been selectively storing and managing system logs, and the retention period for development-environment access records was 90 days. The log management policy was not applied to the newly introduced virtual private network (VPN), and the VPN records were kept for 6 days.
Park Yong-gyu, head of KISA's Digital Threat Response Division, said the team examined multiple angles and completed forensic analysis on the problematic PC, but its verification was limited by the log retention period and it could not secure evidence supporting the attack scenario.
On the 3rd, a briefing on the findings of the Tving public-private joint investigation team was held at the Government Complex Seoul in Jongno-gu, Seoul. Park Yong-gyu, head of KISA's Digital Threat Response Division, Lim Jeong-gyu, director-general for information security and network policy at the Ministry of Science and ICT, and Kim Woo-cheol, head of the cyber incident team, attended the briefing, and the scene was photographed by reporter Kim Ho-jun.
The investigation found that the attacker reached the cloud operations environment after passing through the development environment. Tving was using Amazon Web Services (AWS) cloud services, and the investigation found that access to the operations environment required a separate operations-environment access key.
Among the 361 leaked development projects, 43 operations-environment access keys were included, and the team confirmed that 2 of them were actually exploited. One exploited key was exposed because it had been hardcoded inside the source code, and the investigation found that it was used to access cloud storage. Another exploited key was stored in plain text within configuration values, and it was found to have been used to create a virtual server.
The attacker used these keys to make two unauthorized intrusions into Tving's system, resulting in the leakage of 39.54 million user accounts and 361 development projects.
The Ministry of Science and ICT analyzed the cause of the incident as poor security management by Tving. The ministry explained the incident in connection with Tving's overall lax security management and viewed Tving's key management system as being unorganized.
Analysis of developers' devices by the investigation team confirmed access-key hardcoding and access-key plain-text storage. Hardcoding is a method of entering fixed data directly into source code. Some developers were found to have inserted credentials and cloud-service access keys into source code for convenience.
The background behind this hardcoding was an attempt to reduce the inconvenience of repeated logins when running and checking code. However, hardcoding was pointed out as a security risk that increases the chance of external exposure and makes it easier for attackers to exploit.
The investigation team determined that Tving's operations-environment access keys were not stored separately in an independent storage location. It also found that although Tving had identified access-key hardcoding in a 2024 mock hacking exercise, it did not carry out subsequent corrective measures.
The security industry recommends using a Key Management System (KMS·Key Management System) for the safe management of access keys, and ISMS certification standards also specify that cryptographic keys must be stored in a separate secure location. However, the incident occurred while Tving held ISMS certification, and related controversy surrounding the company now appears unavoidable. In addition to hardcoding, the incident exposed broader key management problems.
Specifically, there was indiscriminate sharing of access keys through internal messengers among developers, and Tving granted all developers access rights to all projects. As a result, the attacker was found to have been able to access all development projects with just one access key.
Tving relied on simple monitoring such as CPU load, and it also had no system in place to detect and block network traffic in real time. During the attacker's first intrusion, abnormal signs were detected, but no alert was generated during the second data-leak attempt, so Tving did not realize it. The investigation team judged that the attacker carried out the attack in a way that limited CPU usage in order to avoid alerts.
The investigation team pointed to shortcomings in Tving's information security governance and judged that among Tving's 265 employees, only 4 were dedicated information security staff, meaning the current staffing level was insufficient to carry out information security activities.
Based on the investigation results, the Ministry of Science and ICT demanded that Tving submit a plan to implement measures to prevent recurrence within September, and the government plans to inspect whether Tving follows through starting in January next year. If the implementation review finds items that need supplementing, the ministry plans to issue a corrective order under Article 48-4 of the Network Act.
The scale of punishment for Tving in connection with this incident has not yet been finalized. For now, the penalties are divided into a fine for the late report and a surcharge that will be decided after the scale of the leak is confirmed.
The Ministry of Science and ICT said Tving became aware of the security incident at 10 a.m. on May 31 and reported it at 3 p.m. on June 1, and plans to impose a fine for the delayed report. The authority responsible for deciding the surcharge is the Personal Information Protection Commission, which will determine the surcharge after assessing the scale of the leak.
The revised Personal Information Protection Act from the commission takes effect on the 11th. The revision includes measures that raise the cap on punitive surcharges for large-scale personal information leaks to as much as 10% of total revenue. However, the Tving leak occurred in May this year, so the incident is known not to be subject to the revised act.
The government is adjusting its response direction, expecting hacking threats to grow and occur more frequently. Lim Jeong-gyu, director-general for information security and network policy at the Ministry of Science and ICT, said hacking threats will intensify due to attackers abusing AI technology and that the frequency of hacking incidents will likely rise in the future. He added that while past response policy focused on reducing incidents themselves, the current approach focuses on rapid response and minimizing harm to the public.
Within this trend, Lim said that under revisions to the Network Act, the government can begin an investigation even before a company reports an incident if signs of a hacking attack are discovered. He said that companies that fail to implement recurrence-prevention measures faithfully are subject to enforcement fines, and that increases in surcharges and fines have also been made. He added that after this series of policy measures is implemented, changes under the first and second pan-government comprehensive cybersecurity plans will become apparent.
Tving held an official apology and explanation session regarding the cyber incident on the 3rd at the Koreana Hotel in Jung-gu, Seoul. Present at the event were Jo Seong-dae, head of the network technology division, Vice President for HR Go Min-seok, CEO Choi Joo-hee, and Jang Hyeon-kyung, head of business management.
Tving announced that it accepts the investigation results. It also said it will faithfully implement all corrective measures and prevention steps to avoid recurrence.
CEO Choi Joo-hee apologized for causing concern and anxiety among customers. She also said the company would position information security as an important responsibility and a source of competitiveness.
CEO Choi Joo-hee also announced plans to expand investment and staffing related to information security. Tving promised to increase its information security investment by about 4 times by 2030 compared with the previous 5 years.
Tving's current information security staffing stands at 4.8 in-house employees, 4.6 outsourced employees, and 9.4 in total. Tving said it plans to add 10 in-house information security employees by the end of this year, and it also presented a plan to expand total in-house and outsourced information security staff to 25 to 30 people within the next 5 years.
The company said it plans to reorganize its security system in a zero-trust direction and strengthen step-by-step verification of authentication and access-control procedures. It will operate permissions under the principle of least privilege, granting only the minimum access needed for job duties and purposes, and it plans to form an 'Information Security Innovation Advisory Committee' directly under the CEO to carry out external expert verification.
As customer compensation, the company offered hacking and phishing safety insurance, premium-level viewing services, Tving points, and entertainment coupons. The safety insurance will be provided for 1 year, and coverage includes cyber financial fraud, online shopping mall fraud, and person-to-person direct transaction fraud caused by hacking and phishing, with a limit of up to KRW 3 million per person.
Current Tving subscribers will automatically receive the premium plan from October to December. The premium plan supports up to 4K resolution and simultaneous viewing on up to 4 devices, and includes Apple TV Originals. Compensation also applies to dormant members and former members, and dormant or former members must re-register to match existing stored information with their identity information.
Compensation can be applied for from the 7th to the 30th of this month through the Tving app and website, and benefits will be applied starting on October 6 regardless of the application process.
Source: IT DAILY · Kim Ho-jun, Kim Byeong-ju
Original: https://www.itdaily.kr/news/articleView.html?idxno=241391
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.