브레이크뉴스 김충열 정치전문기자 = 이정헌 의원(더불어민주당, 서울 광진구갑)이 개인정보보호위원회와 과학기술정보통신부로부터 제출받은 자료에 따르면, 최근 발생한 티빙 해킹 사건의 최종 피해 규모가 1,953만 명으로 공식 확인됐다. 이는 국내 정보유출 사고 중 쿠팡, SKT에 이어 세 번째 규모로, 정부의 초기 잠정치(1,300만 명)보다 650만 명 이상 늘어난 수치다.
![]() ▲ 이정헌 의원은 “대한민국 대표 OTT 기업을 자처하는 티빙이 가장 기초적인 개발자 플랫폼 관리 부실로 인해 국민 1,953만 명의 소중한 개인정보를 해커에게 노출한 것은 기업의 안일함이 부른 명백한 인재(人災)”라고 지적했다. © 사진, 이정헌 의원실/ 김충열 정치전문기자 |
특히 유출 항목에는 민감한 고유 식별 정보가 대거 포함돼 2차 피해 우려가 극에 달하고 있다. 아이디, 이름, 생년월일 외에 비밀번호, 환불 계좌번호, 연계정보(CI), 연계인증정보(DI) 등이 유출됐다. ‘디지털 주민등록번호’로 불리는 CI와 DI는 변경이 불가능해 명의도용 등 금융 범죄에 악용될 위험이 매우 높다.
이에 따라 유출 피해자들의 법적 대응도 본격화되고 있다. 현재 티빙을 상대로 손해배상 소송 참여 의사를 밝힌 원고 규모만 이미 9만 명을 넘어선 상태다. 한 번 유출되면 교체가 불가능한 CI의 특성상, 타 유출 사고 정보와 결합해 완벽한 신원 특정에 악용될 위험이 커 이용자들의 불안과 공분이 확산되고 있다.
티빙의 개인정보 유출 인지 공백도 확인됐다. 티빙은 이상 행위를 5월 30일에 최초 인지했으나, 대용량 파일의 외부 전송을 최종 확인한 것은 사흘 뒤인 6월 2일이었다. 해킹 사실을 알고도 데이터가 빠져나가는 것을 이틀 넘게 파악하지 못한 것이다. 또한 과기정통부와 개보위에 각각 제출된 티빙의 신고서상 최초 인지 시점이 다르게 기재된 경위에 대해서도 정부 부처의 보고 경로 추적과 조사가 진행 중이다.
현재 정부는 유출 규모(1,953만 명)가 티빙의 유료 회원(500만 명) 및 월간 활성 이용자 수(770만 명)를 비정상적으로 초과한 배경을 집중 들여다보고 있다. 탈퇴 회원과 휴면 계정, 통신사 결합 상품 등 타사 제휴를 통해 생성된 계정까지 유출 범위에 포함되었는지가 핵심 분석 대상이다. 티빙이 탈퇴·휴면 계정을 지체 없이 파기하지 않고 무단 방치하여 유출 범위에 포함시켰다면, 이는 과징금 산정 시 중대성을 가중하는 근거로 작용하게 된다.
KISA 정보보호 공시에 따르면, 티빙의 정보보호 투자액은 가입자와 매출 성장세와 달리 최근 2년 새 감소폭이 약 20%에 달했으며, 최고정보보호책임자(CISO)와 개인정보보호책임자(CPO) 직무를 모두 비임원급 인사가 겸직하도록 운영해 온 사실이 드러나, 거대 플랫폼사의 고질적인 보안 불감증이 이번 사태를 키웠다는 지적이 제기된다.
이정헌 “플랫폼 보안 실태 규명 및 제도적 보완책 마련할 것”
이정헌 의원은 “대한민국 대표 OTT 기업을 자처하는 티빙이 가장 기초적인 개발자 플랫폼 관리 부실로 인해 국민 1,953만 명의 소중한 개인정보를 해커에게 노출한 것은 기업의 안일함이 부른 명백한 인재(人災)”라고 지적했다.
이어 이 의원은 이번 사태에 대해 “국내 플랫폼사가 이용자 정보를 얼마나 가볍게 다뤄왔는지를 보여주는 사례”라며 “정부는 이번 조사 결과를 토대로 단순 처벌에 그치지 않고 재발 방지를 위한 제도적 보완책을 마련해야 한다”라고 밝혔다. hpf21@naver.com
*아래는 위 기사를'구글 번역'으로 번역한 영문 기사의[전문]입니다. '구글번역'은 이해도 높이기를 위해 노력하고 있습니다.영문 번역에 오류가 있을 수 있음을 전제로 합니다.*The following is [the full text] of the English article translated by 'Google Translate'. 'Google Translate' is working hard to improve understanding. It is assumed that there may be errors in the English translation.
Rep. Lee Jung-heon Confirms Final Victims of TVING Personal Information Leak Reach 19.53 Million
Leak Exceeds Membership by Four Times... Allegations of Unauthorized Neglect and Downplaying of Withdrawn and Dormant Accounts
Outrage Over Leak of Irreplaceable ‘Credit Information (CI/DI)’ and Refund Accounts... 90,000 Victims Launch Large-Scale Damages Lawsuit
Break News, Political Reporter Kim Choong-lyoul = According to data submitted to Rep. Lee Jung-heon (Democratic Party of Korea, Gwangjin-gu A, Seoul) by the Personal Information Protection Commission and the Ministry of Science and ICT, the final scale of damage from the recent TVING hacking incident has been officially confirmed at 19.53 million people. This ranks as the third-largest data leak incident in Korea, following Coupang and SKT, and represents an increase of more than 6.5 million people compared to the government's initial provisional estimate (13 million).
In particular, the leaked items include a large amount of sensitive unique identification information, raising extreme concerns about secondary damage. In addition to IDs, names, and dates of birth, passwords, refund account numbers, Linked Identity (CI), and Linked Authentication Information (DI) were leaked. CI and DI, often referred to as "digital resident registration numbers," cannot be changed, posing a very high risk of being exploited for financial crimes such as identity theft.
Consequently, legal action by victims of the leak is intensifying. Currently, the number of plaintiffs who have expressed their intention to participate in a lawsuit for damages against TVING has already exceeded 90,000. Due to the nature of CI, which cannot be replaced once leaked, there is a high risk that it could be combined with information from other leaks to perfectly identify individuals, leading to widespread anxiety and outrage among users.
A gap in TVING's awareness of the personal information leak has also been confirmed. Although TVING first detected abnormal activity on May 30, it was not until three days later, on June 2, that it finally confirmed the external transmission of large files. This means that despite knowing about the hacking, the company failed to detect the data leakage for over two days. In addition, government ministries are currently tracing the reporting channels and investigating the circumstances surrounding the discrepancy in the reported timestamps submitted by Tving to the Ministry of Science and ICT and the Personal Information Protection Commission, respectively.
Currently, the government is focusing its investigation on the background of how the scale of the data leak (19.53 million) abnormally exceeded Tving's paid membership (5 million) and monthly active users (7.7 million). The key focus of the analysis is whether the scope of the leak included withdrawn members, dormant accounts, and accounts created through partnerships with third parties, such as telecommunications carrier bundle products. If it is found that Tving included withdrawn or dormant accounts within the scope of the leak by failing to destroy them without delay and leaving them unattended, this will serve as grounds to aggravate the severity of the issue when calculating the penalty fine. According to KISA's information security disclosure, unlike the growth in subscribers and revenue, TVING's investment in information security has decreased by approximately 20% over the past two years. Furthermore, it was revealed that the company operated by having non-executive-level personnel concurrently hold the positions of Chief Information Security Officer (CISO) and Chief Privacy Officer (CPO), leading to criticism that the chronic security complacency of large platform companies exacerbated this crisis.
Lee Jung-hun: “Will investigate the state of platform security and establish institutional safeguards”
Representative Lee Jung-hun pointed out, “The fact that TVING, which claims to be Korea’s representative OTT company, exposed the valuable personal information of 19.53 million citizens to hackers due to negligence in managing the most basic developer platform is a clear man-made disaster caused by corporate complacency.” Representative Lee continued by stating regarding the incident, “This is an example demonstrating how lightly domestic platform companies have treated user information,” adding, “Based on the results of this investigation, the government must not stop at simple punishment but must establish institutional safeguards to prevent recurrence.” hpf21@naver.com


























