The Korean government recently announced the results of their investigation into the hacking of streaming platform Tving. The investigation appears thorough, and the findings are grave. Unidentified hackers stole access keys and compromised highly sensitive information of 39.54 million individuals, along with source code and other technical assets and, crucially, moved these secrets overseas, with the attackers and their country of origin still not identified. The Tving breach included up to 70 types of personal information across 20 categories, including phone numbers, email addresses, dates of birth, and payment histories. Tving missed the 24-hour breach notification requirement and investigators warned the stolen data could fuel further phishing attacks and data theft. By all accounts, the South Korean government’s response – a technical briefing, clear set of findings, company apology, and a referral to the Personal Information Protection Commission (PIPC) to weigh penalties in due course – was measured, professional, and proportionate, though with no penalties to date. Over my