Tving leak confirmed: 39.54 million accounts, what was taken and what to do
If you are a customer of Tving, here’s what is being claimed, and what it would mean for you.
South Korea’s science ministry confirmed on 3 September 2026 that a hack of the streaming service Tving exposed 39.54 million user accounts. Names, birth dates, mobile numbers, emails and login details were taken; resident registration numbers and payment data were not. Anyone who ever had a Tving account — including a forgotten one, or one opened with Kakao, Naver or another social login — may be in that total.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Tving customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On 3 September 2026, South Korea’s Ministry of Science and ICT announced the results of a three-month joint government-civilian investigation into a hack at Tving, the streaming service operated by CJ ENM. The intrusion was detected on 30 May 2026 and reported to authorities on 1 June. Tving had already admitted a leak in its own customer notice in early June, with an apology from its chief executive.
The ministry said 39.54 million user accounts were compromised, along with 361 technical assets including source code. That figure counts accounts, not unique people; some users had more than one. Of the total, 7.26 million were registered directly with Tving, 8.63 million were CJ ONE accounts, and 22.47 million used a social login (Naver, Kakao, Facebook, Apple or X). 22.06 million accounts were still active; 17.37 million were dormant or closed. Stolen data spanned 20 categories and 70 types, depending on how someone signed up, and included names, dates of birth, mobile phone numbers, email addresses, and connecting or login information. Resident registration numbers and payment details were not leaked. An unidentified attacker used a stolen developer access key. Tving says it has strengthened security and that no further attacks have been detected.
What “no ID numbers and no cards” does not mean
Almost every report of this incident does two things in the same breath: it recites 39.54 million, then it underlines that resident registration numbers and payment details were not taken. Both points are true. The second one is real relief. You should not expect this leak, on its own, to produce fraudulent card charges or the kind of identity crime that needs a Korean national ID number.
Here is what that framing skips for a normal person. What the attacker holds is a large, accurate contact list: real names, birthdays, phone numbers and emails, plus login and connecting information — including, for millions of people, the fact that they entered Tving through Kakao, Naver, Facebook, Apple, X or CJ ONE. In ordinary life, that is the set of facts a fake text or a fake phone agent uses to sound legitimate. “They already know my name and my number” is how people get talked into tapping a link or reading out a code.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
It also skips the quiet half of the list. 17.37 million of the accounts were inactive. Closing Tving, leaving an old profile unused, or only ever tapping “Log in with Kakao” does not take you out of the 39.54 million. There is still no official count of unique individuals, only of accounts. None of that changes the practical point: if Tving ever stored your name, birthday, phone and email, that combination is the kind of record that left the company.
This is not a story about emptied bank cards. It is a story about a list of who you are and how to reach you.
What to actually expect
- Tving has said it is notifying users. A genuine notice may arrive. Anyone who then asks you to tap a link, install an app, read out a code, or confirm your birthday and phone number is not helping you.
- The likely near-term follow-on is fraudulent texts and emails. They will mention Tving, CJ, a “39 million leak,” compensation, or a government probe, and they may already show your real name or number. That knowledge comes from the stolen list, not from an official sitting with your case.
- If you opened Tving with Kakao, Naver, Facebook, Apple or X, or with a CJ ONE ID, or you closed the account years ago, you are still in the kind of record the ministry counted. There is no public tool that can honestly tell you whether your name was on this specific list.
- You should not expect card charges or national-ID fraud to spring from this incident. Those items were not taken. The realistic harm is impersonation: someone pretending to be Tving, your carrier, Kakao, Naver or a bank, using details you would expect only a real company to know.
What you can and cannot fix
The names, dates of birth, mobile numbers, email addresses and login IDs taken in this incident cannot be undone. They cannot be deleted from the attackers’ copy, and no company or cleanup service can recall them. If those details were on a Tving account of yours, treat that combination as known.
What still helps, in order:
- Cut down the extra information about you that is for sale on people-search and data-broker websites. A bare leaked record — a name, a birthday, a phone, an email — becomes much more dangerous when it is joined to listings that add relatives, employers and previous addresses. Those listings, unlike the Tving data, can actually be removed. That is the lever you still have.
- Treat your mobile number as the hinge. Name, birthday and phone together are what someone uses to talk a carrier or a call centre into moving your number or resetting an account. Set a separate PIN or extra passcode with your mobile carrier if you have not already, and treat a sudden loss of signal or an unexpected SIM message as urgent.
- Protect the email address that was on the Tving account. That inbox is how most other services prove you are you. A password used only there, and a sign-in prompt on that email, matter here because the address itself is in the leaked set.
- Do not pay, and do not upload ID, to anyone offering to “remove you from the Tving leak.” They cannot. Tving and the ministry have not asked the public to submit documents to check this incident.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
GS25 and GS SHOP data leak confirmed: 1.66 million customers, what it means
South Korea’s privacy regulator has confirmed that an attacker used stolen logins to read personal d…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
IDMerit AI Identity Verification MongoDB Leak — February 2026
A misconfigured MongoDB instance exposed identity-verification records — government IDs, selfies, bi…