In July, South Korea’s government-backed startup support platform, Modu-ui Changup (모두의창업), suffered a data breach. The incident later revealed a critical encryption key management failure, demonstrating how encrypted data can still become exposed when organizations fail to protect encryption keys properly.
The platform supports a nationwide startup audition program overseen by South Korea’s Ministry of SMEs and Startups (MSS), and it stores participants’ personal information, including startup ideas, email addresses, and names.
One month before the reported data breach, concerns had already been raised that applicants’ personal information could be structured and exposed through API responses within the platform. The government stated that it took immediate action. However, it did not disclose whether it had improved the platform’s underlying security architecture.
On June 18, the Ministry of SMEs and Startups announced that personal information and summaries of startup ideas had been leaked. It subsequently launched a detailed investigation together with the National Intelligence Service, the Cyber Security Center, and the National Police Agency.
On July 31, authorities confirmed that the decisive cause of the personal information and startup idea leak was the exposure of an encryption key through an API.
How the Data Breach Occurred
The leaked data had already been encrypted. However, encrypted data requires an encryption key for decryption.
In this incident, the encryption key was exposed together with the API data, resulting in the disclosure of email addresses, evaluation comments, and startup idea summaries belonging to about 5,000 successful applicants.
The Ministry of SMEs and Startups explained that the encryption key had been included within the API. According to the ministry, an external party collected API data through methods such as web crawling, which led to the exposure of the key.
In particular, email addresses configured as private were not visible on the public-facing interface. Nevertheless, investigators determined that they could be obtained through AI-based web crawling.
... continue reading