TVING Announces Enhanced Security Measures, Compensation Claims and National Audit Issues for Users to Review

TVING has announced plans to strengthen its cloud security system following a personal information breach.

Additional compensation claims for affected members will begin on October 6.

The security improvement plan, compensation payments, and National Assembly audit inquiries are each at different stages of progress.

3-Line Summary
1. TVING conducted an AWS security assessment
2. Additional compensation claims will begin on October 6
3. The security enhancement is an announced plan

TVING’s Plan to Strengthen 5 Security Areas

TVING announced on October 2 that it had conducted the SIP, a cloud security assessment and improvement program, with Amazon Web Services (AWS). SIP examines security vulnerabilities and improvement tasks based on the actual cloud environment in use and subsequently supports inspections and improvements.

The areas TVING identified for enhancement are account and permission management, threat detection, infrastructure protection, data protection, and incident response and automation—5 areas in total. It said it plans to inspect assets exposed externally and excessive access permissions, while also establishing a system for centrally managing security policies across multiple AWS accounts.

The response process for detecting anomalies in real time and automatically carrying out necessary measures is also targeted for advancement. The application scope of AWS Network Firewall, Amazon GuardDuty, AWS Security Hub, and Amazon Inspector will be expanded in stages. However, these are follow-up measures and plans announced by TVING, so they should be distinguished from the results of actual implementation and improvement.

According to a Yonhap News report, an investigation into the earlier personal information breach confirmed that information from approximately 3천954만 accounts was leaked, including active, dormant, and withdrawn accounts.

Additional Compensation Claims Accepted Through October 30

TVING announced that it would accept additional claims from affected members who did not apply for compensation during the initial application period. The application period is from 10 a.m. on October 6 through 11:59 p.m. on October 30.

Eligibility can be checked by logging in to the TVING website or app and visiting the compensation application page under the “MY” menu. Members who already completed an application during the previous period cannot submit an additional application, and compensation items cannot be changed after the application is completed.

Members who apply for compensation will receive 1 year of free enrollment in hacking and phishing insurance, 4 months of premium viewing features, 50P in TVING points (equivalent to 5,000 won), and a 1-month Wavve ad-supported Standard pass. The insurance coverage limit is up to 300 ten-thousand won. TVING said compensation is scheduled to be paid sequentially starting at 10 a.m. on November 4.

The National Audit Will Question the Cause of the Incident and Compensation Implementation

Choi Joo-hee, CEO of TVING, was selected as a witness for the National Assembly’s Science, ICT, Broadcasting and Communications Committee’s National Assembly audit on October 6 and the National Assembly audit of the Personal Information Protection Commission by the Political Affairs Committee on October 13.

According to a Sina Ilbo report, the Science, ICT, Broadcasting and Communications Committee plans to question the cause of the TVING hacking incident that occurred last June, the status of the response, and the implementation of customer compensation. The Political Affairs Committee plans to examine the specific circumstances of the personal information breach, management practices, post-incident user protection and compensation measures, and whether plans to improve the personal information protection system have been prepared.

This security enhancement announcement presents the direction of TVING’s response after the incident, while the compensation application is a procedure that eligible members must check themselves. The National Assembly audit is a forum for examining how these response and compensation measures were carried out, making it a separate stage from the others.

References

Tags #TVING #TVINGPersonalInformationBreach #TVINGCompensation #TVINGCompensationApplication #TVINGHacking #TVINGSecurity #AWS #CloudSecurity #PersonalInformationProtection #NationalAssemblyAudit #ChoiJoohee #OTT #TVINGMY