Skip to content
Back to Blog
high severity September 03, 2026 · 5 min read Unverified claim — what this is

Tving leak confirmed: 39.54 million accounts, what was taken and what to do

If you are a customer of Tving, here’s what is being claimed, and what it would mean for you.

South Korea’s science ministry confirmed on 3 September 2026 that a hack of the streaming service Tving exposed 39.54 million user accounts. Names, birth dates, mobile numbers, emails and login details were taken; resident registration numbers and payment data were not. Anyone who ever had a Tving account — including a forgotten one, or one opened with Kakao, Naver or another social login — may be in that total.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Tving leak confirmed: 39.54 million accounts, what was taken and what to do

On 3 September 2026, South Korea’s Ministry of Science and ICT announced the results of a three-month joint government-civilian investigation into a hack at Tving, the streaming service operated by CJ ENM. The intrusion was detected on 30 May 2026 and reported to authorities on 1 June. Tving had already admitted a leak in its own customer notice in early June, with an apology from its chief executive.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The ministry said 39.54 million user accounts were compromised, along with 361 technical assets including source code. That figure counts accounts, not unique people; some users had more than one. Of the total, 7.26 million were registered directly with Tving, 8.63 million were CJ ONE accounts, and 22.47 million used a social login (Naver, Kakao, Facebook, Apple or X). 22.06 million accounts were still active; 17.37 million were dormant or closed. Stolen data spanned 20 categories and 70 types, depending on how someone signed up, and included names, dates of birth, mobile phone numbers, email addresses, and connecting or login information. Resident registration numbers and payment details were not leaked. An unidentified attacker used a stolen developer access key. Tving says it has strengthened security and that no further attacks have been detected.

What “no ID numbers and no cards” does not mean

Almost every report of this incident does two things in the same breath: it recites 39.54 million, then it underlines that resident registration numbers and payment details were not taken. Both points are true. The second one is real relief. You should not expect this leak, on its own, to produce fraudulent card charges or the kind of identity crime that needs a Korean national ID number.

Here is what that framing skips for a normal person. What the attacker holds is a large, accurate contact list: real names, birthdays, phone numbers and emails, plus login and connecting information — including, for millions of people, the fact that they entered Tving through Kakao, Naver, Facebook, Apple, X or CJ ONE. In ordinary life, that is the set of facts a fake text or a fake phone agent uses to sound legitimate. “They already know my name and my number” is how people get talked into tapping a link or reading out a code.

It also skips the quiet half of the list. 17.37 million of the accounts were inactive. Closing Tving, leaving an old profile unused, or only ever tapping “Log in with Kakao” does not take you out of the 39.54 million. There is still no official count of unique individuals, only of accounts. None of that changes the practical point: if Tving ever stored your name, birthday, phone and email, that combination is the kind of record that left the company.

This is not a story about emptied bank cards. It is a story about a list of who you are and how to reach you.

What to actually expect

  • Tving has said it is notifying users. A genuine notice may arrive. Anyone who then asks you to tap a link, install an app, read out a code, or confirm your birthday and phone number is not helping you.
  • The likely near-term follow-on is fraudulent texts and emails. They will mention Tving, CJ, a “39 million leak,” compensation, or a government probe, and they may already show your real name or number. That knowledge comes from the stolen list, not from an official sitting with your case.
  • If you opened Tving with Kakao, Naver, Facebook, Apple or X, or with a CJ ONE ID, or you closed the account years ago, you are still in the kind of record the ministry counted. There is no public tool that can honestly tell you whether your name was on this specific list.
  • You should not expect card charges or national-ID fraud to spring from this incident. Those items were not taken. The realistic harm is impersonation: someone pretending to be Tving, your carrier, Kakao, Naver or a bank, using details you would expect only a real company to know.

What you can and cannot fix

The names, dates of birth, mobile numbers, email addresses and login IDs taken in this incident cannot be undone. They cannot be deleted from the attackers’ copy, and no company or cleanup service can recall them. If those details were on a Tving account of yours, treat that combination as known.

What still helps, in order:

  • Cut down the extra information about you that is for sale on people-search and data-broker websites. A bare leaked record — a name, a birthday, a phone, an email — becomes much more dangerous when it is joined to listings that add relatives, employers and previous addresses. Those listings, unlike the Tving data, can actually be removed. That is the lever you still have.
  • Treat your mobile number as the hinge. Name, birthday and phone together are what someone uses to talk a carrier or a call centre into moving your number or resetting an account. Set a separate PIN or extra passcode with your mobile carrier if you have not already, and treat a sudden loss of signal or an unexpected SIM message as urgent.
  • Protect the email address that was on the Tving account. That inbox is how most other services prove you are you. A password used only there, and a sign-in prompt on that email, matter here because the address itself is in the leaked set.
  • Do not pay, and do not upload ID, to anyone offering to “remove you from the Tving leak.” They cannot. Tving and the ministry have not asked the public to submit documents to check this incident.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Tving is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High contact details only, none of them permanent
Disclosed September 03, 2026
Last reviewed September 3, 2026
Affected Unconfirmed
Data exposed Full namesDates of birthMobile phone numbersEmail addressesLogin IDs and connecting information
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email