Key management system

In July, South Korea’s government-backed startup support platform, Modu-ui Changup (모두의창업), suffered a data breach. The incident later revealed a critical encryption key management failure, demonstrating how encrypted data can still become exposed when organizations fail to protect encryption keys properly.

The platform supports a nationwide startup audition program overseen by South Korea’s Ministry of SMEs and Startups (MSS), and it stores participants’ personal information, including startup ideas, email addresses, and names.

One month before the reported data breach, concerns had already been raised that applicants’ personal information could be structured and exposed through API responses within the platform. The government stated that it took immediate action. However, it did not disclose whether it had improved the platform’s underlying security architecture.

On June 18, the Ministry of SMEs and Startups announced that personal information and summaries of startup ideas had been leaked. It subsequently launched a detailed investigation together with the National Intelligence Service, the Cyber Security Center, and the National Police Agency.

On July 31, authorities confirmed that the decisive cause of the personal information and startup idea leak was the exposure of an encryption key through an API.

How the Data Breach Occurred

The leaked data had already been encrypted. However, encrypted data requires an encryption key for decryption.

In this incident, the encryption key was exposed together with the API data, resulting in the disclosure of email addresses, evaluation comments, and startup idea summaries belonging to about 5,000 successful applicants.