MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-08-24 · via BleepingComputer

Encryption key left in API led to South Korean startup data leak

A breach at South Korea's government-backed startup platform Modu-ui Changup exposed personal data of about 5,000 applicants. Investigators found the encryption key was included in the API, allowing AI-based web crawling to decrypt email addresses and startup idea summaries. The incident highlights the risks of hard-coding encryption keys within application code or configuration files.

Expanded Detail

The breach at Modu-ui Changup involved roughly 5,000 successful applicants in a nationwide startup audition program run under South Korea's Ministry of SMEs and Startups. Investigators traced the exposure to an encryption key embedded directly within the platform's API, which allowed automated web-crawling tools to decrypt fields that were not even visible on the public interface, including private email addresses and evaluation comments. Authorities identified 39 South Korean IP addresses linked to the data access and noted that the investigation was still examining possible ties to AI solution providers. The case underscores that encrypted data offers little protection when the key travels alongside the data itself, and that remediation requires more than key rotation—organizations must re-encrypt affected records, review access logs, and reassess permissions across their entire infrastructure.

Context

This incident could erode public trust in government-run digital services, particularly among entrepreneurs who submit sensitive business ideas and personal details to state-backed platforms. If encryption keys are mishandled in one agency's system, applicants may become more cautious about participating in similar programs, potentially reducing engagement with legitimate startup support initiatives. The case may also pressure other organizations to audit their own key management practices, though smaller entities lacking dedicated security teams could struggle to implement the necessary safeguards.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “South Korean startup platform breach exposes key management failures.” Browse more stories.