Add to Google Preferred Sources
Tving issued a formal apology on September 3 alongside a comprehensive compensation and security overhaul plan following a recent personal data breach. The compensation package includes one year of cyber safety insurance covering hacking and phishing-related financial fraud up to ₩3 million (approximately $2,200) per person, automatic upgrade to premium viewing, ₩5,000 (approximately $3.7) worth of Tving points, and a choice between a Wavve AVOD one-month pass or a CGV combo discount coupon. Applications run from September 7 to 30, with benefits effective October 6. Approximately 17 million deactivated and dormant accounts will also be eligible upon re-registration. On the security front, Tving will expand information security investment to roughly four times the previous five-year average by 2030, reaching ₩10–12 billion (approximately $7.3–8.8 million) annually, while tripling its security workforce over the next five years. The company will transition to a Zero Trust architecture and establish a CEO-level advisory committee.
Key Elements
Tving announced on September 3 a compensation package of up to ₩3 million (approximately $2,200) per affected customer and a fourfold expansion of information security investment in response to a recent personal data breach.
Choi Ju-hui, CEO of Tving, held a press briefing at the Koreana Hotel in Gwanghwamun, Seoul, where she issued a formal apology and outlined recurrence prevention measures and compensation plans. “I sincerely apologize for the deep concern and anxiety this breach has caused our customers,” she said. “As CEO, I bear a heavy responsibility for failing to provide a safe service to those who trusted and used Tving.”
The customer compensation package announced that day consists of four components: cyber safety insurance, premium viewing upgrade, Tving points, and entertainment coupons. The safety insurance is provided for one year and covers up to ₩3 million per person for cyber financial fraud stemming from hacking and phishing, internet shopping mall fraud, and person-to-person direct transaction scams.
Viewing environments will be automatically upgraded to premium tier without a separate application. Additionally, ₩5,000 (approximately $3.7) worth of Tving points (50p) will be issued, and customers may choose between a Wavve AVOD one-month pass (valued at ₩5,500) or a CGV combo discount coupon of ₩5,000. Compensation applications will be accepted from September 7 to 30, with benefits effective from October 6. Applications can be submitted through the official Tving app and website.
The company stated that approximately 17 million deactivated and dormant account holders will also be eligible for the same compensation upon re-registration. However, Tving made clear it will not reduce content investment.
Tving also pledged a complete overhaul of its security infrastructure. The company will pursue four key strategies: expanding information security investment and personnel, rebuilding a Zero Trust-based security architecture, re-establishing organizational governance and security culture, and strengthening expertise through external collaboration.
Specifically, Tving will expand information security investment to approximately four times the previous five-year average by 2030. Current annual investment of ₩2–3 billion (approximately $1.5–2.2 million) will be raised to ₩10–12 billion (approximately $7.3–8.8 million) per year. The in-house dedicated security team will grow from the current 4 members to 10 by year-end, with approximately 15–16 total including external personnel by year-end, and up to around 30 over the next five years. The specialized workforce will expand to three times its current size over the next five years.
The security organization will be subdivided into product security, cloud security, enterprise IT security, and compliance security functions. Authentication and access control will transition to a phased verification system based on Zero Trust principles, applying the principle of least privilege—granting access only within the scope necessary for specific roles and purposes. Systems and network segments will be separated to block internal intrusions, and AI-based detection systems will enable immediate blocking and isolation upon risk detection.
On the governance front, Tving will establish a working-level security council under the CEO-CISO/CPO structure, creating a framework that spans from security issue identification through decision-making, execution, and auditing. Role-specific security training and hands-on simulation drills will be institutionalized. Additionally, a CEO-level Information Security Innovation Advisory Committee will be launched to institutionalize objective verification by external experts.
The Public-Private Joint Investigation Team determined that it became aware of the breach at 10 a.m. that day, while Tving became aware at 3 p.m. Accordingly, the company will comprehensively restructure CISO and CPO governance and conduct additional AI-assisted reviews of the 361 leaked
“We will fundamentally rebuild our entire security framework,” Choi emphasized. “Information security will be treated as the company’s most important responsibility and competitive advantage, and we will expand both security investment and personnel.”
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
