Telecom

Tving to Expand Security Staff to 30, Compensate Departed Members Over Data Leak

IT DAILY ·

Choi Joo-hee, CEO of Tving, is apologizing at a briefing on the cyber intrusion incident on the 3rd. [Photo: Reporter Kim Byeong-ju]

✦ AI Summary

Tving said it would apologize for the large-scale data leak and accept the findings of the joint public-private investigation team, while fundamentally rebuilding its security framework.

It plans to increase its information security staff to 10 by the end of the year, expand internal and external security staff to as many as 30 over the next 5 years, and increase information security investment to about 4 times the level of the previous 5 years by 2030.

The compensation pool for leaked data now extends to dormant members and former members, and includes hacking and phishing insurance, a premium viewing experience, Tving points, and entertainment coupons.

Tving said it would accept the findings of the joint public-private investigation team, apologize for the large-scale data leak, and fundamentally rebuild its overall security framework. Tving CEO Choi Joo-hee attended a briefing on the cyber intrusion incident at the Koreana Hotel in central Seoul on the 3rd and said the company would reflect on the incident and make the changes.

Accordingly, Tving plans to expand its information security staff to 10 by the end of the year. It also plans to increase internal and external security staff to as many as 30 over the next 5 years, and to roughly triple its pool of dedicated security specialists over the same period.

It will also expand investment in the medium to long term. Tving said it plans to increase information security investment to about 4 times the level of the previous 5 years by 2030. In addition, it intends to subdivide its security organization into product security, cloud security, enterprise IT security, and compliance security.

The scope of compensation for leak-related damage has also been broadened. Tving said it will include dormant members whose personal information was leaked and former members who had withdrawn from the service but whose personal information was leaked.

Tving disclosed a detailed plan to expand staffing. As of last year, Tving had 9.4 information security staff members, with 4.8 internal staff and 4.6 external staff. Tving said it plans to increase its internal information security staff to 10 by the end of this year and to expand total internal and external information security staff to about 25 to 30 over the next 5 years.

The Ministry of Science and ICT's joint public-private investigation team pointed to Tving's information security dedicated workforce of about 4 people. The comparable development workforce stood at 149. The team judged that with that staffing level, it would be difficult to carry out information security activities such as round-the-clock security monitoring and vulnerability checks.

In response, Tving said it will apply the zero-trust principle to its security system and revise authentication and access control into a step-by-step verification model. It will also shift to a minimum-privilege framework based on job role and purpose, and separate system and network domains on the assumption of internal intrusion. It will further strengthen AI-based anomaly detection and reinforce its real-time automated response system. In addition, it plans to form an "Information Security Innovation Advisory Committee" directly under the CEO and seek verification from outside experts.

The government investigation found that Tving had failed to fix a security vulnerability it had already identified. Tving discovered in a 2024 simulated hacking test a source code exposure vulnerability in the access key for its development and operations environment, but did not remedy it. The investigation team pointed to poor access key management and the absence of systems to detect and respond to abnormal activity.

At the site briefing, Tving said the reason it did not address the vulnerability was that the handover and management process for related work had been insufficient. Tving also said it had conducted a full survey of related vulnerabilities after the incident and strengthened security measures.

Meanwhile, Tving said it is difficult to estimate the scale of damage from the 361 development projects leaked in the incident. According to the Ministry of Science and ICT investigation, the volume of leaked technical assets was 30.35 GB, including source code for user recommendation and search algorithms, source code for the authentication system, source code for payment management, and source code related to paid-service operations.

Tving said the 361 items were source code needed to develop its service, and added that it had carried out a full vulnerability inspection through a private security company and completed verification by the investigation team.

It added that it is conducting additional vulnerability analysis using AI and plans to continue improving any vulnerabilities it discovers.

As compensation for customers, it will provide hacking and phishing insurance, a premium viewing experience, Tving points, and entertainment coupons. The insurance coverage period is 1 year, and the coverage includes cyber financial fraud, online shopping mall fraud, and private transaction fraud arising from hacking or phishing. The coverage limit is up to KRW 3 million per person. Current Tving subscribers will be provided with a premium viewing experience offering up to 4K quality and 4-device simultaneous viewing from October to December without separate application. Users affected by personal information leakage will receive Tving points worth KRW 5,000 that can be used for individual content purchases, and as optional benefits they will also be offered either a 1-month Wavve AVOD pass or a CGV combo discount coupon.

Compensation will also extend to dormant members and former members. However, re-registration is required to compare existing stored information with personal information, and paid subscription is not required.

Tving said the estimated perceived value of the compensation package is about KRW 20,000 per person. However, it said it would not disclose the total compensation cost, citing variables such as the number of applicants and the actual compensation items selected by users.

Tving said that despite the burden of compensation costs, it has no plan to reduce investment in original content or sports. It also said it will continue its policy of expanding its global business and reinvesting in content.

The compensation application period runs from the 7th to the 30th, and applications can be submitted through the Tving app and website. Compensation will begin on October 6.

Source: IT DAILY · Kim Byeong-ju
Original: https://www.itdaily.kr/news/articleView.html?idxno=241390

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.