A South Korean joint public-private investigation found that a late-May breach at streaming platform Tving exposed 39.54 million accounts, including 22.06 million active, 17.37 million inactive and 110,000 test accounts, with duplicates meaning one person held as many as 13 accounts. By channel, social media sign-ups including NAVER and Kakao totaled 22.47 million, or about 57%, followed by 8.63 million CJ ONE memberships and 7.26 million direct Tving accounts. Exposed data spanned 70 types across 20 categories, including IDs, passwords, names, phone numbers, emails, dates of birth and Connecting Information (CI), which investigators previously described as the first identified mass CI leak. Attackers struck over May 29–31 by stealing a development access key left in plain text in source code—a flaw flagged in a 2024 penetration test but left unfixed—then harvested production keys across 361 projects, breached cloud storage holding the user database and moved data to overseas accounts still under police inquiry; no secondary dark-web harm has been confirmed. At a September 3 briefing, CEO Choi Joo-hee apologized and said Tving will quadruple information-security investment by 2030, expand staffing, adopt zero-trust controls and give affected customers identity-protection insurance, 5,000 won in points and additional viewing benefits.