CJ ENM(035760) Tving rolled out customer compensation and information security innovation plans in connection with the personal information leak that occurred in June. It will increase information security investment by about four times compared with the previous five years by 2030 and expand its security professionals to three times the current level. For affected customers, it will provide hacking and phishing protection insurance, along with Tving points and content discount coupons.

On the 3rd, Tving held a press briefing at Koreana Hotel in Jung District, Seoul, and announced an official apology for the personal information leak, along with plans to strengthen its information security system and compensate customers.

Tving CEO Choi Ju-hee said, "I sincerely apologize for causing concern and anxiety to customers due to this breach," and added, "Since the incident, we have cooperated faithfully with the investigation, implemented urgent security measures, and worked to protect customers." Choi bowed and said, "We will responsibly implement recurrence prevention measures to restore customers' trust."

Choi Ju-hee, CEO of Tving, announces an official apology for the personal data leak, along with plans to strengthen information security and compensate customers, at the Koreana Hotel in Jung-gu, Seoul, on the 3rd. /Courtesy of Tving

Tving prepared mid- to long-term information security innovation plans through verification and advice from outside experts. It will promote four key strategies: ▲ expanding information security investment and security personnel ▲ rebuilding a zero-trust-based security system ▲ strengthening security governance and organizational culture ▲ establishing a verification system through external experts.

Information security investment will be expanded by about four times compared with the previous five years by 2030, and the number of security professionals will be increased to three times the current level over the next five years. The security organization will also be subdivided by field, including product, cloud, enterprise IT, and compliance.

It will also strengthen access rights management. Under zero-trust principles, it will continuously verify authentication and access and apply the principle of least privilege. Assuming internal compromise, it will segment systems and networks and raise the protection level for critical data such as personal information. It also plans to strengthen AI-based detection and real-time automated response systems.

It will revamp security governance as well. Under a CEO–CISO/CPO structure, it will create a working-level security council and build a response system that runs from identifying security issues through decision-making, execution, and inspections. It will launch a CEO-direct "Information Security Innovation Advisory Committee" to receive objective verification and advice from external experts.

The compensation plan consists of hacking and phishing protection insurance, an upgrade to a premium viewing environment, Tving points, and entertainment coupons.

Hacking and phishing protection insurance will be provided for one year and will compensate up to 3 million won per person not only for cyber financial fraud but also for online marketplace fraud and person-to-person direct transaction fraud. It will also offer a benefit that automatically upgrades users to a premium viewing environment without a separate application. In addition, it will grant Tving points worth 5,000 won that can be used to purchase the latest films individually. For entertainment coupons, users can choose either a one-month Wavve AVOD pass (5,500 won) or a 5,000-won discount coupon for three CGV combo sets.

The application period for the compensation package runs from Sept. 7 to 30, and the benefits will take effect starting Oct. 6.

Meanwhile, before the press briefing, a public-private joint investigation team under the Ministry of Science and ICT announced the results of its investigation into Tving's personal information leak. The investigation team confirmed that a total of 39.54 million accounts were leaked, including 22.06 million active accounts, 17.37 million inactive accounts, and 110,000 test accounts. There are 8.5 million dormant accounts and 8.87 million withdrawn accounts. Not only personal information but also Tving's technology assets, including development projects, was found to have been leaked.

※ This article has been translated by AI. Share your feedback here.