It was found that 39.54 million user accounts and 361 pieces of development source code containing core service technology were leaked from the online video service (OTT) Tving. The attack began with the theft of a developer access key and led to the theft of an operations environment access key that was left exposed in the source code, and because the user information databases (DB) inside the operations environment were not encrypted and were stored in plain text, personal information leaked out wholesale.

The Ministry of Science and ICT on the 3rd announced the findings of a public-private joint investigation team into the Tving breach.

Illustration = ChatGPT

◇ Names, mobile phone numbers, email addresses, dates of birth, and more stolen

According to the investigation team, a total of 39.54 million accounts (including duplicates) were leaked. There were 22.06 million active accounts that can log in, 17.37 million inactive accounts including dormant (8.5 million) and withdrawn (8.87 million), and 110,000 test accounts. Because a Tving account is structured so one person can have multiple accounts, it differs from the actual number of users. In fact, there was a confirmed case where one user had up to 13 accounts.

By sign-up channel, there were 7.26 million Tving direct sign-ups, 8.63 million CJ ONE integrated members, and 22.47 million simple sign-ups via social media (SNS) such as Naver and Kakao.

The investigation team said the information leaked in the breach included a total of 20 items (70 types), including ▲ID ▲passwords (one-way encrypted) ▲CJ ONE integrated ID ▲name ▲mobile phone number ▲email address ▲date of birth ▲connected information (CI, a unique value used to identify an individual as a substitute for a resident registration number) ▲refund account number (encrypted) ▲partner service information (22 types) ▲payment history (11 types), among others. Accounts whose CI was leaked numbered 19.04 million.

Mobile phone numbers and email addresses were leaked in a partially encrypted state, but because the encryption key was leaked together, decryption is possible, so they were found to be at the same level as information leaked in plain text. Passwords were leaked in a one-way encrypted state and cannot be decrypted to plain text, the investigation team said.

In addition to user information, 361 development projects (30.35GB) containing technology needed to operate the Tving service—such as user-tailored content recommendation and search algorithms, user management and authentication systems, payment management, and paid service operations—were leaked. The investigation team is concerned that the attacker could analyze this source code to find vulnerabilities and exploit them for further attacks. No signs of additional attacks have been identified so far, and Tving is strengthening its own security measures, including conducting vulnerability assessments within the development projects through a private security company.

/Courtesy of the Ministry of Science and ICT

◇ A door opened by a single development key

The cause of the incident was found to be poor access key management. The attacker stole a developer-held "development environment" access key and infiltrated the internal systems (development and operations environments).

Tving's "development environment" is a developer collaboration platform where source code is stored and multiple developers simultaneously modify and manage it. To access the development environment, each developer needs an individual access key. The investigation team said it identified the developer using the access key exploited for the personal information leak and analyzed various possibilities through device forensics—whether the key was stolen via phishing, malware, a supply chain attack, or because the developer shared or misused the development key—but could not confirm the cause.

The attacker exfiltrated 361 development projects from the development environment and obtained the "operations environment" access key stored there. Then, inside the operations environment, the attacker found that the access information (ID, PW) for the user DB was not encrypted and was stored in plain text, and stole it.

After accessing the user DB, the attacker extracted information on 39.54 million accounts. On the first attempted data exfiltration on May 30, an anomaly alert was triggered as the central processing unit (CPU) utilization of the DB server spiked to 100% due to excessive workload, and Tving, upon checking the alert, took action to block the task. The next day, in the second attempted exfiltration, the attacker limited CPU utilization to within 10% so that no anomaly alert would be triggered, the investigation team estimated. Inside the operations environment, the attacker created a virtual server, used it as a channel for exfiltration, and deleted the virtual server after the leak.

◇ Only four dedicated staff, report filed more than 24 hours late

This investigation revealed gaps in Tving's information protection system. The investigation team pointed out that because Tving granted all developers access rights to all projects, the structure allowed the entire project set to be exposed if just one access key was compromised. It also found that Tving developers either exposed, without concealment, access keys for the development and operations environments inside the source code (hard-coding) or stored them in plain text without concealment through encryption processing. Even after identifying a hard-coded access key vulnerability in its own 2024 penetration test, Tving did not take corrective action.

Despite having a total workforce of 265 and 149 developers, Tving had only four dedicated information protection staff excluding contractors. It was about 14 hours after 6 p.m. on May 30, when anomalies occurred, that the situation was shared with the chief information security officer (CISO), who oversees incident response.

The report was also late. Under the Act on Promotion of Information and Communications Network Utilization and Information Protection, Tving was required to report within 24 hours of recognizing the breach, but it reported to the Korea Internet & Security Agency (KISA) at 3:08 p.m. on June 1, about 29 hours after 10:10 a.m. on May 31, when the information security team disseminated the situation.

※ This article has been translated by AI. Share your feedback here.