2026 Tving — confirmed third-party leak; CEO apology; ~15M+ cited in trade press (June 3)
Data compromised
Names, DOB, sex, phones, usernames, emails; viewing history cited in social/trade reporting
Technical writeup
On June 3, 2026, Korean streaming platform Tving confirmed that an unauthorized external party leaked member personal information—including names, dates of birth, sex, phone numbers, usernames, and email addresses—while stating resident registration numbers and payment data were not stored and therefore unaffected. The Korea JoongAng Daily reported the company apologized, strengthened monitoring, and advised password changes for reused credentials; South Korea’s Ministry of Science and ICT opened an investigation the same day. Criminal-forum and security-social channels cited roughly 15 million or more affected accounts and viewing-history exposure; Tving had not published an official victim total at catalog time, so BreachHistory uses the trade-press ceiling with ongoing verification.
Root cause
Unauthorized external party access to user data (third-party leak per company notice)
References
- https://koreajoongangdaily.joins.com/news/2026-06-03/business/industry/Streaming-service-Tving-confirms-third-party-data-leak/2607425
- https://databreaches.net/2026/06/03/kr-tving-ceo-apologizes-for-unprecedented-data-leak/
- https://koreajoongangdaily.joins.com/news/2026-06-03/business/industry/Tving-faces-investigation-by-Ministry-of-Science-ICT-following-personal-data-breach/2607818