[Fact Check] “Were KTCorporation, Naver, and Kakao Compromised Too?”… Misconceptions and the Truth Behind the TVING Data Breach Affecting 19.53 Million Users
Users of the Three Major Telecom Carriers, Naver, and Kakao Are Already Among Those Whose Data Has Been Compromised
"Not a Hacking Incident at a Partner Company"... Government Investigation Confirms Possibility of CI Abuse
[Edaily Reporter Kim Hyun-ah ] Concerns are spreading following the recent TVING personal data breach, as claims have emerged that customers using partner services—such as KTCorporation, Naver, and Kakao—have also been affected. There are fears that, in addition to the 19.53 million users officially identified by TVING as affected, the systems of its partner companies may have also been compromised in a chain reaction.
However, this is not accurate. To put it simply, subscribers through the three major telecom carriers and users of Naver and Kakao’s one-click login services are already included in the total of 19.53 million users affected by the breach, as announced by TVING. In other words, this is a single incident in which member information stored in TVING’s own database (DB) was leaked, not a case where partner companies’ systems were hacked.
Generative AI
① Users of the three major telecom carriers’ partnership plans are already TVING members
The office of Rep. Lee Jeong-heon of the Democratic Party of Korea stated, “The personal information of approximately 416,000 users who received TVING subscription vouchers from KTCorporation as customer compensation was also included in the data breach.” While some may mistakenly believe that KTCorporation’s system was hacked, this is a misunderstanding of the data flow.
Subscribers to telecom partnership plans merely receive TVING subscription vouchers (such as codes) from their telecom providers. To actually use the TVING service, customers must sign up directly with TVING and enter their personal information.
A KTCorporation spokesperson stated, “This incident was caused by an external intrusion into the DB of TVING’s operator and is unrelated to KTCorporation’s systems,” adding, “KTCorporation has neither provided nor entrusted customers’ personal information to TVING.”
CJ ENM CO., Ltd.(035760) The spokesperson also explained, “Users who signed up through partnerships with telecom carriers such as SKTelecom, KTCorporation, and LG Uplus are ultimately registered as TVING members, so they are already included in the 19.53 million users affected by this data breach.”
② Easy Login Is Merely a Means of Authentication
The situation is the same for users who utilize Easy Login via their Naver or Kakao accounts. Easy Login is a method by which users authenticate themselves using their Naver or Kakao accounts when signing up for or logging into TVING.
During this process, if the user consents, information necessary for service provision—such as name, email address, and mobile phone number—is transmitted to TVING, which then stores it in its own DB. Therefore, if the TVING DB was compromised, the information of users who used easy login is also included in the data breach.
It is important to note that, to date, there is no evidence that Naver or Kakao’s login systems or servers were hacked.
An official from the government’s public-private joint investigation team explained, “The fact that users of the simplified login feature are included in the data breach does not represent a new instance of damage; rather, this information was already within the scope of the existing Tving member data breach,” adding, “Interpreting this as a separate incident could inflate the actual scale of the damage.”
③ Account Hijacking Is Difficult Based on CI Leak Alone
The primary concern for the security industry and users is whether CI (Connecting Information), used in the simplified login process, has been leaked. CI is a unique identifier issued by identity verification agencies to identify individuals instead of resident registration numbers.
Experts explain that it is technically difficult to log in to other sites or hijack accounts using CI alone. This is because CI is a value used to identify users, not login credentials. Furthermore, since it can be reissued by changing the encryption key used to generate it, it is not a permanent identifier.
However, there is a possibility of an exceptional risk if certain websites, due to design flaws, have implemented the CI to function like a login ID. Experts explain that this is not a vulnerability inherent to the CI itself, but rather a problem stemming from the flawed design of the service in question.
The security industry believes that since the actual level of risk may vary depending on the specific items of leaked information and how each service utilizes them, it is necessary to confirm this through the findings of the government’s joint public-private investigation team.
④ Remaining Challenges: Determining the Exact Scope of the Data Breach and Assigning Responsibility
The essence of this incident is that it was not a hack of a telecommunications company or portal, but rather a breach of the customer database (DB) stored by TVING.
Experts point out that this incident highlights the need to clarify responsibilities for personal information protection and incident response systems within a platform ecosystem where simplified login and partner services have expanded.
The specific personal information items that were actually leaked, whether confidential information (CI) was compromised, and the potential for secondary damage are expected to be confirmed through the findings of the government-private sector joint investigation team.
"We expect capital expenditures (CAPEX) for 2026 to be in the mid-to-high 2 trillion won range. Our future investment strategy will be determined by striking a balance that takes into account future c…
IL SCIENCE CO.,LTD.(307180)announced on the 22nd that it is rapidly expanding its humanoid robot business by broadening the supply of its humanoid robot “ILBOT” to various industries, while also accel…
AprilBio Co.,Ltd. Logo (Photo courtesy of AprilBio Co.,Ltd.)
AprilBio Co.,Ltd. has acquired a dual-target small interfering RNA (siRNA)-based therapeutic candidate for metabolic diseases from Curi…