Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [incident, data-breach, confirmed-breach, south-korea, encryption, key-management, api, government] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: false

Modu-ui Changup South Korean Startup Platform Breach (2026-08-24)

South Korea's Ministry of SMEs and Startups, investigating with the National Intelligence Service (NIS) and National Police Agency, confirmed that the Modu-ui Changup startup-support platform leaked data for about 5,000 successful applicants because an API response exposed the encryption key alongside the encrypted data it protected.

Overview

Attribute Detail
Organisation Modu-ui Changup startup-support platform (South Korean government)
Status Confirmed breach
Data exposed Email addresses, evaluation comments, startup-idea summaries
Volume ~5,000 successful applicants
Root cause API response exposed the encryption key alongside encrypted data
Investigators Ministry of SMEs and Startups, NIS, National Police Agency
Attribution detail 39 South Korean IP addresses identified accessing the data

What Happened

Despite privacy settings, crawlers harvested the exposed applicant data โ€” reportedly including AI-based crawling โ€” once the API returned the encryption key together with the ciphertext. Authorities identified 39 South Korean IP addresses accessing the data during the investigation.

Significance

The case is a textbook demonstration that encryption without key management is decoration: encrypting data at rest provides no protection when the key ships with the data. It carries a procurement lesson for government agencies generally, including under NZISM key-management guidance.

Source