Key Points
- Executives from major Korean platforms including streaming service Tving and cosmetic surgery app Gangnam Unni were summoned to the National Assembly audit over severe security breaches.
- Lawmakers slammed Tving for leaking nearly 40 million accounts and source codes despite explosive revenue growth, while Gangnam Unni exposed sensitive cosmetic consultation photos belonging to users a
- Platform chiefs publicly apologized, pledging to drastically expand cybersecurity investments and adopt Zero Trust frameworks to curb secondary damage.
Summary South Korea's top digital platform leaders faced severe scrutiny at the National Assembly's Science, ICT, Broadcasting and Communications Committee audit following a wave of major cybersecurity breaches and sensitive data leaks. Executives from leading streaming service Tving, digital payment gateway Toss Payments, and popular cosmetic surgery consultation platform Gangnam Unni took the witness stand to publicly apologize and answer for critical security negligence.
Lawmakers directed intense criticism at Tving, the nation’s prominent homegrown streaming platform. During the hearing, Representative Lee Jeong-heon revealed that a massive breach had compromised 39.54 million accounts along with the service's underlying source code. Compounding the issue, developer credentials were left stored as unencrypted plain text directly inside the source code, allowing 24 gigabytes of data to be extracted via virtual servers undetected by internal monitoring. Tving also violated statutory obligations by failing to report the breach within the legally required 24-hour window. Lawmakers highlighted that while Tving experienced explosive financial growth over the past five years—with revenue soaring 26.2-fold from 15.5 billion won to 406.8 billion won—its dedicated cybersecurity team consisted of merely four employees. Tving CEO Choi Ju-hee admitted that rapid corporate expansion led to underinvestment in security, acknowledging that previously flagged vulnerabilities from a 2024 penetration test had not been completely eliminated.
The audit also tackled high-profile breaches affecting everyday consumer life and medical privacy. Toss Payments faced questions over the mass leakage of payment receipts after anomaly detection systems failed to flag suspicious activity, prompting CEO Lim Han-wook to announce compensation vouchers for affected merchants and intensified oversight. Meanwhile, Hong Seung-il, CEO of Healing Paper—which operates the medical and beauty platform Gangnam Unni—issued a formal apology after sensitive records belonging to over 220,000 users across 103 countries were exposed. The leak included consultation photos, desired cosmetic procedure areas, and purchased service records. Lawmakers condemned the platform for leaving roughly 6,000 photo URLs publicly accessible even after discovering the intrusion, alongside failing to secure proper consent for sensitive medical data.
To address the fallout and prevent secondary damage, the executives pledged sweeping overhauls. Tving committed to transitioning toward an enterprise-grade Zero Trust security architecture, while Gangnam Unni promised to triple its security workforce, increase security investments by 2.5 times, and establish dedicated support centers and compensation for affected global users.
Sponsored · Ad