South Korean startup platform leaks encrypted data
A South Korean government-backed startup platform leaked personal data on about 5,000 people who applied to a national startup program. The data was encrypted, but the decryption key was exposed alongside it, so encryption gave no real protection.
- Report priority
- Medium
- Involves
- Modu-ui Changup
What is known
The platform's API responded with data that included the encryption key needed to unlock the encrypted fields, and an outside party collected that API data through web crawling, including AI-based crawling that pulled out email addresses meant to stay private.
What to do
There is no personal check a reader can run. This affects only people who applied and were selected through South Korea's Modu-ui Changup startup audition platform, and the Ministry of SMEs and Startups has confirmed the leak affects roughly 5,000 successful applicants.
Reported details
Modu-ui Changup, South Korea's national startup audition platform, stores applicants' names, emails, and startup idea summaries. An outside party crawls the platform's API with automated tools, including AI-based crawling. Because the API response bundles the encryption key together with the encrypted data, the crawler ends up with both the locked data and the key that unlocks it, exposing emails, evaluator comments, and startup idea summaries for about 5,000 successful applicants.
The root cause was hard-coded key management: the platform's API response included the encryption key needed to decrypt the personal-data fields it was returning, so encrypting the data provided no real protection once the API itself was exposed. Fields marked private, such as applicant email addresses, were not shown on the public interface but were still reachable through the API and were extracted via automated and AI-based web crawling. Authorities traced access to 39 IP addresses, all located in South Korea, and are investigating further connections.
References
- securityweek.com · personal-information-exposed-in-apollo-global-data-breach SecurityWeek
- infosecurity-magazine.com · exposed-aws-key-data-charities Infosecurity Magazine
- neuracybintel.com · ringcentral-data-breach-exposes-personal-details-of-16-million-accounts-in-shinyhunters-extortion-campaign NeuraCybIntel
- neuracybintel.com · trezor-shipping-partner-breach-exposes-personal-data-of-nearly-14000-hardware-wallet-customers NeuraCybIntel