Tving Reveals Compensation Plan for Dormant and Former Users After Personal Data Leak
TECHWORLD ·
✦ AI Summary
After Tving officially announced its personal data leak on June 3, it held an apology briefing on the third.
At the briefing, it disclosed the incident details, a customer compensation plan, and security reinforcement measures.
The leaked information consisted of customer data and 361 items of source code needed for service development, and compensation applications are open until September 30.
After Tving officially announced the personal data leak, it held an official apology briefing on the third and explained the circumstances of the incident and follow-up measures. The official announcement of Tving's personal data leak came on June 3.
At the briefing, the company disclosed the incident details, announced a customer compensation plan, and laid out its security reinforcement plans. The leaked information consisted of customer data and 361 items of source code needed for service development.
The company said there had been insufficient consistent application of security rules during service changes, and that the resulting attack led to the leak. Tving also acknowledged shortcomings in its response system during the incident response process.
Tving said it plans to provide a customer compensation package in line with its responsibility for the leak and has begun compensation for customers whose information was confirmed to have been exposed. Eligible users include dormant customers and former customers, and each person will receive compensation valued at about KRW 20,000. In addition, Tving unveiled plans to expand its security workforce, increase security investment, and strengthen security measures.
The compensation will be offered as a package combining multiple benefits, consisting of hacking and phishing protection insurance, an upgraded premium viewing environment, Tving points, and entertainment coupons. Tving said the compensation value is about KRW 20,000 per customer.
The hacking and phishing protection insurance will be provided for 1 year, and it covers cyber financial fraud stemming from hacking and phishing, online shopping mall fraud, and peer-to-peer direct transaction fraud. The insurance coverage limit is up to KRW 3 million per person. The premium viewing environment upgrade does not require a separate application and will be applied automatically. Tving points worth KRW 5,000 for individual purchases such as the latest movies will be provided. The entertainment coupon will be offered as a choice of one of two options: 1 month of Wavve AVOD or a KRW 5,000 discount coupon for a CGV Combo set of 3 items.
The compensation will be based on the customer, not the account. Dormant customers are eligible for compensation if they suffer harm from the personal data leak, and former customers are also eligible if they suffer harm from the leak.
However, former customers must first go through a re-registration procedure for identity verification and basic information matching before applying. The deadline to apply for compensation is September 30, and compensation will begin to be applied from October 6.
Tving explained why it prepared the compensation plan, rolled out the compensation package, and provided the protection insurance as well. The purpose is to help customers feel more secure and to make the value of the compensation more tangible. Tving said it believed the reason for offering the protection insurance was that, even if it is not directly linked to damage compensation, it would contribute to safer use in the future.
Separately from the compensation package, Tving is also pushing ahead with its own security improvements. It plans to triple its internal and external security workforce within the next 5 years, and it plans to increase investment by 4 times compared with the previous 5-year period by 2030.
Its staffing plan includes adding 10 people to the internal information organization by the end of this year. After that, hiring will continue and be adjusted depending on the scale of investment.
Tving plans to fully upgrade its security fundamentals to zero trust and rebuild its security culture. It will also establish a working-level security council to build a swift and consistent response system, and launch an Information Protection Innovation Advisory Committee directly under the CEO to advance security policies and technical systems.
As Tving management said the incident underscored the need to overhaul security across the board, CEO Choi Joo-hee said she deeply regretted the incident and that the company would fundamentally rebuild its security system. She also said information protection is the platform's most important responsibility and competitive edge, and pledged to do its utmost to restore customer trust.
Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406513
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.