News

39.5 Million Accounts Leaked, Including the Identifier Koreans Cannot Change

Moca Network
September 10, 2026

A government investigation into the breach of Korean streaming platform Tving, announced on 3 September 2026, put the exposure at 39.54 million accounts. The headline number is larger than the platform’s subscriber base, which is the first thing worth understanding about it. The second is what was inside: alongside names, phone numbers, dates of birth and payment histories sat connecting information, the identifier that links one Korean person across the services they use.

Key takeaways

  • The joint public and private investigation, led by the Ministry of Science and ICT, found 39.54 million accounts compromised, against an initial estimate of 19.53 million.
  • 17.37 million of those accounts were inactive, split between dormant accounts and accounts belonging to people who had already withdrawn.
  • The data spanned 20 categories and 70 data types, including connecting information (CI), the cross-service identifier derived from a resident registration number.
  • Some phone numbers and email addresses were encrypted, but the encryption keys were compromised too.
  • Access keys had been stored in plain text in source code. The weakness was documented in a 2024 penetration test and not fixed.
  • Two more Korean platforms disclosed breaches in the same week, and the penalty ceiling for large Korean breaches has just moved to 10 percent of total revenue.

What the investigation found

The attack ran between 29 and 31 May 2026 and was reported on 1 June. An attacker used a stolen developer access key to reach internal systems. Three months later the investigation resolved the question that had hung over the early reporting, which was how a platform with roughly five million paying subscribers could produce a victim count in the tens of millions.

Account typeAccounts
Active22.06 million
Dormant8.50 million
Withdrawn8.87 million
Test0.11 million
Total39.54 million

The answer is that the figure counts accounts, not people, and that a single person can appear several times through different sign-up routes. Around 57 percent of the affected accounts were social sign-ups through Naver or Kakao, with the remainder split between a group membership programme and direct registrations. Alongside the account records, 361 technical assets including source code were taken.

The part that cannot be reissued

Most of the compromised fields have a remedy. A password is rotated, a card is reissued, a phone number can in principle be changed. Connecting information has no equivalent.

CI is a Korean identifier generated from a resident registration number and used across services in place of that number, precisely so that the number itself does not have to circulate. The design works because the same person always resolves to the same value. That property is also what makes a leak consequential: a CI held by an attacker is a stable key for joining records taken from unrelated breaches into a single profile of one individual, and for aiming targeted fraud at that person. The company has said resident registration numbers and valid payment details were not exposed because it does not store them, which is the correct decision and also demonstrates the limit of it. The derivative was enough.

The encryption detail compounds this. Some phone numbers and email addresses had been encrypted at rest, which is the control most organisations would point to first in a breach notification. The keys went with them.

Nearly half the records belonged to people who had left

Of the 39.54 million accounts, 17.37 million were dormant or withdrawn. Those are records of people who had stopped using the service, in many cases people who had actively closed their account, and whose identity data was still present to be taken years later.

Retention of this kind is rarely a deliberate decision. It accumulates from reconciliation needs, statutory record-keeping periods, analytics tables, backups and the general absence of any process that deletes anything. The breach converts that accumulation into a liability with a precise size, and it lands on a population that has no ongoing relationship with the company and no reason to expect exposure from it.

It was not an isolated week

Two other Korean platforms disclosed incidents within days.

PlatformScaleExposed
Streaming (Tving)39.54 million accountsNames, phone numbers, emails, dates of birth, payment histories, CI, source code
Fan community (Weverse)422,584 recordsInternal identifiers, purchase and refund records, payment provider, amounts and timestamps
Cosmetic medical marketplace (Gangnam Unni)~220,000 usersContact details, consultation records, photographs and payment information, via unauthorised API access

The three have little in common commercially. What they share is a data posture: each collected verified identity attributes at sign-up because Korean platforms routinely do, each retained them, and each became a single point at which those attributes could be taken in bulk.

The penalty side moved first

Korean enforcement has been repricing this risk through 2026. In June the Personal Information Protection Commission fined an e-commerce operator 624.9 billion won, roughly 409 million US dollars, over a breach affecting about 33.7 million accounts. Amendments to the Personal Information Protection Act, passed on 12 February 2026, authorise administrative fines of up to 10 percent of a company’s total revenue where it acts intentionally or with gross negligence in cases affecting 10 million or more individuals, alongside expanded reporting duties and a named ultimate responsible person for data protection.

Public-sector exposure is moving in the same direction. Korean reporting in August 2026 recorded 164 state-run institutions disclosing personal data incidents in the first half of the year alone, above the 128 recorded across the whole of 2025.

The design question

A breach of this shape is usually read as a security failure, and the access key in plain text, flagged in 2024 and left in place, supports that reading. The retention pattern points somewhere else. Every one of those 39.54 million records exists because a platform needed to establish who someone was at sign-up, and then kept the evidence of that check indefinitely because there was no mechanism that required it to stop.

The alternative worth examining is not stronger encryption of the same archive. It is whether a relying party needs to hold the underlying attributes at all, or whether it can accept a credential issued elsewhere, verify it, and retain only the proof that verification occurred. Minimal data custody does not remove the issuer’s own obligations, and someone in the chain still holds identity data. It does change how many copies exist, how long each survives after the relationship ends, and how much a single stolen developer key is worth.

Frequently asked questions

How many accounts were affected by the Tving data breach?

A joint public and private investigation led by South Korea's Ministry of Science and ICT, announced on 3 September 2026, put the figure at 39.54 million accounts: 22.06 million active, 17.37 million inactive, and 110,000 test accounts. The inactive group splits into roughly 8.5 million dormant and 8.87 million withdrawn accounts. The count is of accounts rather than distinct people, and it exceeds the platform's subscriber base because many people hold more than one account across sign-up channels.

What is connecting information, and why does its exposure matter?

Connecting information, or CI, is a Korean identifier derived from a resident registration number and used in place of that number for online identity verification. Because the same person receives the same CI across services, it functions as a durable cross-service link. A leaked CI can be used to join records from separate breaches into a single profile of one individual, and unlike a password or a phone number it is not something the person can rotate.

How did the attackers get in?

Investigators found that access keys had been stored in plain text inside source code rather than in a dedicated secrets repository, and that an attacker used a stolen developer access key to reach internal systems between 29 and 31 May 2026. The same weakness had been identified in a penetration test in 2024 and had not been remediated. Alongside account data, 361 technical assets including source code were taken.

Were resident registration numbers or payment card details leaked?

The company has said resident registration numbers and valid payment card details were not exposed because it does not store them. The compromised set spanned 20 categories and 70 data types, including IDs and one-way encrypted passwords, names, mobile phone numbers, email addresses, dates of birth, payment histories and connecting information. Some phone numbers and email addresses were encrypted, but the encryption keys were compromised as well.

What penalties does South Korea now apply to large data breaches?

In June 2026 the Personal Information Protection Commission fined an e-commerce operator 624.9 billion won, about 409 million US dollars, over a breach affecting roughly 33.7 million accounts. Amendments to the Personal Information Protection Act passed on 12 February 2026 authorise fines of up to 10 percent of total revenue where a company acts intentionally or with gross negligence in cases affecting 10 million or more individuals, taking effect six months after enactment subject to transition rules.

Related reading

Sources: Ministry of Science and ICT joint public-private investigation findings, 3 September 2026, as reported by Seoul Economic Daily and The Korea Herald; Korea Herald and Music Business Worldwide on the Weverse disclosure; Korea JoongAng Daily on the Gangnam Unni disclosure; Personal Information Protection Commission enforcement reporting, June 2026; Personal Information Protection Act amendments passed 12 February 2026.

What we’re building at AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Hong Kong Rewrote Its Remote Onboarding Rules Around Deepfakes
The HKMA's new circular replaces its 2019 and 2021 remote onboarding guidance with two principles: prove the document is genuine, and link the customer to it.
News
Spain Ruled Stored Face Templates Unlawful, and the Defence Was Security
Spain's regulator ruled stored face templates are special category data and fined an identity provider €950,000. The provider says removing them weakens security.
News
Windows 11 Will Tell Apps How Old You Are, but Not When You Were Born
Microsoft documented a Windows 11 API that hands apps an age band instead of a birth date. Apple and Google already ship one. None of them verify the age.