Modu-ui Changup South Korean Startup Platform Breach (2026-08-24)
South Korea's Ministry of SMEs and Startups, investigating with the National Intelligence Service (NIS) and National Police Agency, confirmed that the Modu-ui Changup startup-support platform leaked data for about 5,000 successful applicants because an API response exposed the encryption key alongside the encrypted data it protected.
Overview
| Attribute | Detail |
|---|---|
| Organisation | Modu-ui Changup startup-support platform (South Korean government) |
| Status | Confirmed breach |
| Data exposed | Email addresses, evaluation comments, startup-idea summaries |
| Volume | ~5,000 successful applicants |
| Root cause | API response exposed the encryption key alongside encrypted data |
| Investigators | Ministry of SMEs and Startups, NIS, National Police Agency |
| Attribution detail | 39 South Korean IP addresses identified accessing the data |
What Happened
Despite privacy settings, crawlers harvested the exposed applicant data โ reportedly including AI-based crawling โ once the API returned the encryption key together with the ciphertext. Authorities identified 39 South Korean IP addresses accessing the data during the investigation.
Significance
The case is a textbook demonstration that encryption without key management is decoration: encrypting data at rest provides no protection when the key ships with the data. It carries a procurement lesson for government agencies generally, including under NZISM key-management guidance.