Tving, the OTT platform whose personal information of about 19.53 million users was leaked, will issue an official apology on the 3rd. It is the first such apology in three months since the breach was disclosed. What criteria were used to design the compensation plan announced alongside the apology is of keen interest to users and the industry.
At 4 p.m. on the 3rd, Tving will hold a briefing at a hotel in Jung-gu, Seoul, attended by CEO Choi Joo-hee and other top executives to announce measures to strengthen information security and customer compensation plans. The company said it would offer an official apology and explain the circumstances, adding, “We deeply apologize for the concern and inconvenience caused.”
How much was leaked?
The incident occurred on the evening of May 30. An unidentified hacker gained unauthorized access to a database containing user information and extracted files. Tving confirmed the breach the following day, reported it to authorities on June 1, and notified users on June 3.
The scale of the leak became clear through materials submitted to the National Assembly. According to data from the office of Rep. Lee Jung-heon of the Democratic Party of Korea, about 19.53 million people were affected. Considering that Tving has around 5 million paid subscribers, it is believed that information from former users who had left the service was also left on the server and leaked together.
What made the breach worse was the type of information exposed. In addition to basic details such as IDs, names, dates of birth, gender, mobile phone numbers, and email addresses, the leak also included identity verification information such as CI and DI, refund account numbers, and even encrypted passwords.
CI is a unique number created based on the resident registration number and used for identity verification online. Passwords can be changed, but names, dates of birth, and CI cannot be changed for life. Because information that can identify the same person across multiple sites was leaked together, experts warned of a heightened risk of misuse for targeted phishing and identity theft.
User backlash led to legal action. Eight days after the breach notice, on June 11, a law firm filed a damages suit on behalf of 1,051 users, and the number of applicants to join it surpassed 100,000 within a week.
What to watch in the compensation plan
The key point in this announcement is the 기준 for compensation. In many cases of personal data leaks, there is no immediately visible financial loss, so the scope of compensation can vary greatly depending on how far the company recognizes harm. The first benchmark is whether Tving emphasizes remedies within its service, such as free extension of subscriptions or point payments, or whether it focuses on responding to external harm with cash-equivalent compensation or identity theft prevention services.
Previous cases will serve as comparisons. Last year, after a leak of U.SIM information affecting its subscribers, SK Telecom offered free SIM replacement, exemption from cancellation fees, and bill discounts, and received a 134.8 billion won fine from the Personal Information Protection Commission. Late last year, information from roughly 33 million Coupang accounts was leaked, sparking controversy over compensation. Tving users are likely to judge this announcement by asking whether a level of compensation similar to SK Telecom’s will be offered.
Another point that needs explanation is why information from former members was retained. The Personal Information Protection Act requires that information for which its purpose has been fulfilled be destroyed without delay. The reason why data equivalent to four times the number of paid subscribers was stored on the server, and how the retention period will be reduced going forward, are considered core aspects of the security measures.
The timing of the apology is also drawing criticism. At the time of the breach notice, CEO Choi released an apology saying, “We will take responsibility to the end,” but it took three months for the management to appear in person and deliver an official apology and compensation plan. Since investigations by the Personal Information Protection Commission and the police are ongoing, additional fines and measures may follow depending on the results.
What users should do now
Separate from the compensation plan, there are steps users should take themselves. If you have not yet changed your Tving password, do so, and change the passwords on other sites where you use the same one. The leaked password was encrypted, but attacks that match breached information from different sources have long been common.
Be wary of texts and phone calls that appear to come from someone who knows your name, date of birth, and mobile phone number. It is safest to assume that any message asking you to verify an account or click a link while pretending to be Tving or a financial institution is suspicious. Users whose refund account numbers were leaked can contact their bank and turn on alerts for suspicious transactions. By signing up for identity theft prevention services offered by telecom companies and financial institutions, you can receive notifications if someone attempts to open an account or activate a line using your information.
It is not too late to decide whether to join the class-action lawsuit after reviewing the compensation plan. Accepting compensation from the company does not necessarily mean losing the right to sue, but some compensation offers may include settlement clauses, so the terms should be checked carefully.