In July, Modu-ui Changup, a South Korean government-backed platform supporting startup programs, experienced a data breach. This platform is overseen by the Ministry of SMEs and Startups (MSS) and stores personal information, including startup ideas, email addresses, and names, for participants in a nationwide audition program.
Authorities confirmed on July 31 that the primary cause of the data leak was the exposure of an encryption key through an API. The leaked data, which included email addresses, evaluation comments, and summaries of startup ideas for about 5,000 successful applicants, was already encrypted. However, the exposed key allowed for its decryption.
The Ministry of SMEs and Startups explained that the encryption key was included within the API. An external party collected API data, potentially through web crawling, which led to the key's exposure. Even email addresses configured as private were obtainable through AI-based web crawling, according to investigators.
This incident underscores the risks associated with hard-coding encryption keys directly into application code, configuration files, or databases. When keys are managed this way, they can become vulnerable to exposure alongside the systems or data they are intended to protect, compromising the security of otherwise encrypted information.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
South Korea's government-backed startup platform, Modu-ui Changup, experienced a data breach in July that exposed personal information and startup ideas of approximately 5,000 applicants. The incident was caused by an encryption key being exposed through an API, allowing encrypted data to be decrypted and accessed by external parties.