Data Breaches at Tving and Weverse Expose Millions of South Korean Users
Security failures at streaming giant Tving and K-pop hub Weverse compromised millions of records and critical technical assets.
South Korea's digital entertainment sector is facing a cybersecurity crisis following massive data breaches at streaming giant Tving and K-pop hub Weverse. The incidents have exposed the personal information of millions of users and compromised critical technical infrastructure.
Tving suffered the more severe blow, with a leak affecting 39.54 million accounts. The breach included 22.1 million active accounts, 8.5 million dormant accounts, 8.9 million withdrawn accounts, and 110,000 test accounts. The stolen data spanned names, dates of birth, phone numbers, email addresses, payment histories, and personal identifiers. Beyond user data, the breach compromised 361 technical assets, including the platform's source code.
Simultaneously, Weverse—the global fan platform operated by a Hybe subsidiary for acts like BTS and Seventeen—reported a breach affecting 422,584 records. The exposed data included internal identification numbers and detailed purchase information, such as payment methods, currency, amounts, and transaction statuses. Weverse Company stated that the leaked internal identifiers do not contain names or contact information and are unlikely to enable payment fraud on their own.
Systemic Vulnerabilities
These breaches occur as South Korea rapidly expands its digital entertainment exports. While Weverse serves as a primary gateway for global K-pop fandom and Tving operates as one of the nation's largest domestic streaming services, both have demonstrated systemic vulnerabilities in how they handle massive volumes of consumer data. The scale of the Tving leak is particularly alarming because the compromise of source code and technical assets can provide attackers with a roadmap for future exploits.
Industry Implications
The fallout from these events puts immense pressure on the Korean entertainment industry to evolve its security posture. For years, many platforms have relied on basic regulatory compliance, but the loss of nearly 40 million records at Tving suggests that current frameworks are insufficient. The industry must now shift toward high-investment, robust cybersecurity architectures to protect a global user base that is increasingly targeted by sophisticated actors.
Next Steps
Both companies have issued apologies and are currently implementing security upgrades and compensation measures for affected users. While Weverse maintains that its leak posed a lower risk of direct identity theft, the Tving breach remains a critical concern due to the depth of the personal identifiers leaked. Industry observers are now watching for how South Korean regulators will penalize these platforms and whether this will trigger a wider security audit across the country's entertainment tech sector.