Categories Entertainment

Korean Entertainment Services Suffer Significant Data Breaches

Major Data Breaches at Weverse and Tving: A Cybersecurity Wake-Up Call

South Korean entertainment platforms Weverse and Tving have recently suffered significant data breaches, affecting millions of user accounts and raising alarms about cybersecurity vulnerabilities within the digital entertainment sector.

Weverse Breach Details

Weverse, a global fan platform managed by Weverse Company (a subsidiary of Hybe), has revealed that approximately 420,000 user accounts were compromised. This platform serves as a direct-to-fan hub for popular music acts, including BTS and Seventeen. The breach followed an external report that highlighted a potential security vulnerability.

  • Critical exposed data included internal identification data, payment details, and transaction histories. However, Weverse emphasized that the internal identifiers alone do not reveal users’ names or contact information, potentially mitigating risks of payment fraud or unauthorized transactions.

Tving Breach Insights

In a separate but similarly concerning incident, Tving, one of South Korea’s leading streaming services, suffered a larger breach affecting nearly 39.5 million accounts. An investigation revealed that:

  • 22.06 million were active accounts, while 17.37 million were inactive, and 110,000 were test accounts.
  • Compromised data included personal information like names, mobile numbers, and payment histories. Although some data had been encrypted, the keys for that encryption were also breached.

The identity of the attackers remains unknown, but no secondary damages have been reported as of now.

Responses and Measures

In light of these breaches, both companies have taken steps to bolster their cybersecurity:

  • Weverse Company has improved API access controls and reduced the exposure of internal identification data.
  • Tving announced a significant investment in cybersecurity through 2030, pledging to increase funds for security fourfold compared to the last five years. They have also introduced a compensation package for affected users, including a one-year insurance program covering financial fraud.

Conclusion

These incidents underscore the critical need for heightened cybersecurity measures in the digital entertainment industry. As user data becomes increasingly vulnerable, both Weverse and Tving are implementing stronger security protocols to protect their user base and mitigate future risks.

Affected users can apply for compensation until September 30, although applications must be submitted manually to qualify for benefits.

Leave a Reply

您的邮箱地址不会被公开。 必填项已用 * 标注

You May Also Like