The government’s investigation into TVING’s personal data breach became more specific on September 3, 2026. The investigation team determined that information from 39,540,697 accounts, including duplicate accounts, had been leaked. TVING also announced plans to compensate customers and expand its security investments. Users should distinguish between the total number of accounts, the information actually involved, whether their own account is included in the inquiry, and the schedule and conditions for applying for compensation.
Key Changes
The first figure to distinguish in this announcement is “39.54 million accounts.” This number includes duplicate accounts and is not the same as the actual number of affected users. The investigation also identified cases in which one person held up to 13 accounts. Therefore, 39,540,697 accounts must not be interpreted as 39.54 million affected people.
The leaked accounts were categorized as 22 million active accounts, 17.37 million inactive accounts, and 1.1 million test accounts. The investigation also found that 361 development projects containing source code and approximately 30.35 GB of technical assets had been leaked externally, in addition to user information.
The scale of the number of accounts and the actual number of affected users do not mean the same thing.
Current Status
The personal information identified in the investigation included 70 types across 20 categories, including user IDs, passwords, names, telephone numbers, email addresses, dates of birth, CI, DI, and payment histories. After receiving TVING’s report on June 3, 2026, the Personal Information Protection Commission began investigating the specific circumstances of the breach, the extent of the damage, and compliance with the law. As of September 3, 2026, however, the Commission’s final calculation of the damage and any sanctions for legal violations had not been finalized.
There is a difference between the government investigation team’s and TVING’s assessments of when the incident was recognized. The investigation team determined that TVING recognized the incident at 10:10 a.m. on May 31, while TVING reportedly identified 3:09 p.m. that day as the recognition time. TVING reported the cybersecurity incident to the Korea Internet & Security Agency at 3:08 p.m. on June 1.
The investigation team explained that the intrusion into internal systems involved the theft and inadequate management of developer access keys, and that a virtual server in the operating environment was exploited as a channel for data leakage. This describes the intrusion process and management issues identified in the investigation; it does not establish the attacker’s identity or confirm additional damage.
Impact on Users
TVING announced that affected customers would receive one year of hacking and phishing protection insurance, with compensation of up to KRW 3 million per person. It also said it would provide KRW 5,000 worth of TVING Points that can be used for individually purchased content, such as newly released movies.
The entertainment coupon benefit was presented as a choice between two options. Users can choose either a one-month Wavve ad-supported VOD pass or a KRW 5,000 discount coupon for a CGV Combo 3 set. Applications for the compensation package are scheduled to run from September 7 through September 30, and the benefits are expected to take effect on October 6.
| Category | Confirmed details |
|---|---|
| Protection insurance | One year provided; compensation of up to KRW 3 million per person announced |
| Points | KRW 5,000 worth of TVING Points for individually purchased content |
| Choice of coupon | One-month Wavve ad-supported VOD pass or CGV discount coupon |
| Application period | September 7–30, 2026 |
| Expected start date | October 6, 2026 |
However, users should check TVING’s subsequent official notices in the app and on its website for the eligible recipients, application method, and detailed coverage terms of the protection insurance. It cannot be assumed that the maximum compensation limit applies equally to every type of damage or that all users will receive the same benefits.
On TVING’s official personal data breach inquiry page, users can log in or verify their identity to check whether their personal information was leaked and which categories were involved. Even if you receive a breach notification, verify the official TVING domain and sender before opening any link from an unclear source. Users should also remain alert to phishing or smishing attempts impersonating breach notifications.
Next Dates to Check
The nearest key date is September 7, when applications for the compensation package are scheduled to open. The application deadline is September 30, and the benefits are expected to begin on October 6. During this period, users should check official notices in the TVING app and on the website for the eligible recipients, application process, and insurance policy terms.
As part of its prevention measures, TVING said it would increase information-security investment to approximately four times the level of the previous five-year period by 2030 and expand its security workforce to about three times its current size. Separately from the compensation schedule, the results of the Personal Information Protection Commission’s investigation into the extent of the damage and legal compliance will need to be confirmed through subsequent announcements.
The order for users to check is straightforward. First, use the official inquiry page to confirm whether your account was affected and which information was involved. Next, review the official notice for the compensation eligibility requirements and application period. Finally, check the insurance coverage and required application procedures against the policy terms. Avoid entering additional personal or authentication information through unverified links or sources.