On June 3, 2026, South Korean OTT platform Tving confirmed that an unauthorized external party leaked member personal information and posted a public apology on its website. According to the Korea JoongAng Daily, exposed categories include names, dates of birth, sex, phone numbers, usernames, and email addresses; resident registration numbers and payment data were reportedly not stored. The Ministry of Science and ICT opened an investigation the same day.
Viewing history and scale uncertainty
Security-social channels cited 15 million or more accounts and viewing-history exposure, but Tving had not published an official denominator at catalog time. Criminal sellers often inflate streaming-app dumps by merging recycled credentials—treat megaleak counts as ceilings until South Korea’s PIPC or Tving files attested numbers.
Immediate steps for subscribers
- Change your Tving password and any reused passwords on CJ-affiliate services.
- Enable app-based MFA on email accounts used for recovery.
- Be skeptical of “free premium extension” phishing referencing real watch history.
Canonical record: Tving 2026 third-party leak on BreachHistory.
Sources: Korea JoongAng Daily, DataBreaches.net