South Korea says a government-backed startup support platform leaked personal data and startup idea summaries for about 5,000 successful applicants. The affected platform, Modu-ui Changup, supports a Ministry of SMEs and Startups program. Authorities said the root cause was an encryption key exposed through an API, allowing data collected through web crawling to be decrypted; investigators traced access to 39 South Korea-based IP addresses.
Why it matters: Affected applicants may face privacy risks and exposure of commercially sensitive startup ideas even though the data was stored in encrypted form. Organizations should review API responses, rotate and re-encrypt compromised data, and separate encryption keys from application-accessible data paths.
Sponsored by Penta Security
2026.08.24
100% relevant
This article establishes a distinct breach event and provides the key technical finding: the platform's API exposed the encryption key that let attackers decrypt data gathered from the service.
← Back to all stories