The breaches compromise nearly 40 million Tving accounts and more than 420,000 Weverse records

Tving CEO Choi Ju-hui bows in apology during a press conference held in Seoul on Thursday. (Yonhap)
Tving CEO Choi Ju-hui bows in apology during a press conference held in Seoul on Thursday. (Yonhap)

Popular South Korean entertainment platforms Weverse and Tving are grappling with major data breaches, renewing the spotlight on cybersecurity risks facing the country’s digital entertainment industry.

Weverse, the global fan platform operated by Hybe subsidiary Weverse Company, has confirmed a security breach that compromised the personal data of approximately 420,000 user accounts. The mobile and web platform serves as a direct-to-fan hub for major music acts, hosting Hybe talents such as BTS and Seventeen alongside a broad roster of artists represented by third-party agencies.

Weverse Company apologized Sunday night after discovering the breach in response to an external report flagging a potential security vulnerability.

The incident affected 422,584 records at the account ID level. The exposed information included internal identification data, an identifier generated when users sign up for the service and used to distinguish individual accounts within Weverse Company’s systems. Other exposed data included purchase type, payment provider, currency, purchase amount, canceled amount, purchase date and time, purchase status, and refund date and time.

In response, Weverse Company said it strengthened access controls for the API that processes payment information and removed internal identification data to avoid external exposure.

Weverse Company added that the exposed internal identification data does not directly identify users, as it does not contain names or contact information. The identifiers are used solely within the company’s internal systems and cannot be used externally, the company said, adding that the exposed information alone is unlikely to enable payment fraud or unauthorized fund transfers.

The Weverse breach came shortly after Tving, one of Korea’s largest domestic streaming services, recently faced a larger security incident.

An investigation by the Ministry of Science and ICT found that approximately 39.5 million Tving accounts and source-code files had been compromised.

The affected accounts included 22.06 million active accounts, 17.37 million inactive accounts — including dormant and terminated accounts — and 110,000 test accounts.

The compromised information covered 20 categories and 70 types of data, including users’ names, mobile phone numbers, email addresses, dates of birth and payment histories. Some phone numbers and email addresses had been encrypted, but the encryption keys were also compromised, potentially allowing attackers to restore the data to its original form.

No secondary damage has been officially reported to date, and the attacker's identity remains unknown.

Regarding the recent findings, Tving held a press briefing in Seoul on Thursday, where it pledged to significantly increase its investment in information security and expand its cybersecurity workforce. By 2030, the company plans to spend roughly four times the amount it has invested in security over the previous five years to bolster its internal cybersecurity capabilities.

The streamer also unveiled a compensation package for users affected by the breach.

At the center of the package is a one-year insurance program providing coverage of up to 3 million won ($2,200) per person for cyber financial fraud, online shopping fraud and person-to-person transaction fraud resulting from hacking or phishing attacks. Tving will also provide entertainment-related compensation, including 5,000 won worth of Tving points.

Eligible users can apply for compensation from Monday through Sept. 30. The compensation will not be issued automatically, and affected members must submit an application to receive the benefits.


yoonseo.3348@heraldcorp.com