Key Takeaways
Three Korean platform companies, Tving, Toss Payments, and Healingpaper, came under sharp criticism in a National Assembly audit over recent data breach incidents.
The cases involved tens of millions of Tving accounts, large volumes of Toss Payments receipt data, and sensitive information from more than 220,000 users of Gangnam Unni across 103 countries.
All three companies apologized and pledged stronger security investment, customer support, and measures to prevent repeat incidents.
The more convenient a platform becomes, the more expensive a leak can be. That was the blunt lesson from a parliamentary audit in Seoul, where recent breaches at Tving, Toss Payments, and Gangnam Unni, a Korean beauty and medical booking platform, were put under the microscope.
The real issue was not only the scale of each incident. Lawmakers also questioned whether the companies had responded too slowly after the attacks and whether they had treated security as a core infrastructure need rather than a controllable expense. The hearing exposed what looks like a growing security debt across Korea's platform industry.

One breach can damage trust more than once
Tving, a Korean streaming service, was first to face intense questioning before the National Assembly's science and ICT committee. Chief executive Choi Joo-hee expressed regret and admitted security lapses. Lawmakers said 39.54 million accounts and source code had been exposed, that developer access credentials had been left in plain text rather than encrypted, and that 24 gigabytes of data had been drained without proper monitoring. A delay in reporting the incident beyond the legal deadline made the case look less like a single intrusion and more like a breakdown in overall management.
Tving said it had already provided phishing prevention steps and points coupons to affected customers, but compensation alone cannot fully restore trust. Data leaks can push users away and erode the safe, reliable image a brand has built over time. That is especially true for entertainment and payment platforms, where users often hand over personal information almost as a condition of use. Tving's case showed again that a content platform does not get a lighter version of the security obligation.
Payment and medical data carry greater risk
The cases involving Toss Payments and Healingpaper were even more sensitive. Toss Payments, which provides payment processing services, was criticized for failing to properly detect signs of abnormal activity when large volumes of payment receipts were leaked. Chief executive Lim Han-wook acknowledged shortcomings and said the company was compensating merchants with cash-equivalent gift certificates while strengthening internal reviews and oversight of partner merchants.
Healingpaper, which operates Gangnam Unni, faced questions after information linked to more than 220,000 users in 103 countries was reportedly exposed, including desired treatment areas, purchased services, and photos. In a platform that mixes beauty and medical services, such data is not ordinary profile information. It touches some of the most sensitive parts of a person's private life. Chief executive Hong Seung-il said the company deeply regretted failing to protect sensitive personal information and noted that the firm had received an information security management system certification in 2024, but still suffered the breach. That admission underscored a simple point: certification is only a minimum standard, not proof of real-world defense.
Security needs to be built in, not added later
All three companies responded with the same familiar promise: more people, more spending, and better controls. Healingpaper said it would more than triple its security staff and increase security investment by 2.5 times. It also promised 50,000 points in compensation, legal support for secondary damage, and a dedicated counseling center. Toss Payments also pledged tighter management of merchants and partners. These responses are necessary, but they are still emergency treatment. The real cost was already incurred earlier, when security was allowed to sit too low on the priority list.
The larger question raised by the audit is not which company should be punished most harshly, but why companies move only after the same kinds of failures repeat. Korean platforms have grown by collecting user data as a business asset. As that data accumulated, so should have the responsibility to protect it. Yet the industry has often treated defense systems as invisible overhead while focusing on features and user growth. The result is a cycle of apologies, compensation, and promises that sound similar every time a breach occurs.

Post-incident compensation is only the beginning
An apology and a support plan can start a response, but they do not end the problem. Coupons for victims and counseling centers matter, but they do not answer the harder questions: Has stolen data already spread in the market? Can it be leaked again? Are there weak points in contractors or outsourced systems? Larger platforms also tend to have more complicated organizations and more outside links, which makes responsibility blurrier. After an incident, the key question should be less about who speaks for the company and more about who performs the final security check before anything goes wrong.
The three companies at the center of this debate operate in different fields, but they share one trait: they all depend on user data as fuel for their services. That makes security not an optional add-on but a core part of the business model. Whether the service is streaming, payments, or medical and beauty bookings, once data leaks, the trust behind the service is damaged too. Fixing slogans after the fact is not enough. Companies must decide from the start what data they collect, how long they keep it, who can access it, and what trace those actions leave behind.
The audit left one clear question
If this criticism becomes a one-time episode, the same scene will repeat. Regulators and lawmakers now need to look beyond corporate apologies and examine whether the system itself works. Are breach reporting rules effective in practice? Does information security certification such as ISMS really function as a minimum line of defense? Do especially sensitive platforms need their own standards? Not every incident can be prevented by law, but repeated blind spots can at least be reduced.
In the platform era, competitiveness is no longer defined only by speed or flashy recommendation systems. The way a company handles data is part of the service itself. The apologies and promises made at the audit came too late, but they should now be more specific. The public does not want abstract pledges to hire more security staff. It wants proof that those workers can actually prevent the next breach. If platforms continue to ignore that basic demand, the next round of criticism will sound very much like this one.