South Korea Overhauls Startup Platform Following API Data Breach

Desk

korocamia@naver.com | 2026-08-01 07:18:59


SEOUL — South Korea’s Ministry of SMEs and Startups (MSS) has disclosed the root cause of a recent data breach on its "Startup for All" platform and announced a comprehensive security overhaul.

At a press briefing on July 31, Acting Minister Noh Yong-seok revealed that a joint investigation with the National Intelligence Service (NIS) identified critical flaws in the platform’s Application Programming Interface (API). Unintended private data was embedded into the API, and encryption keys were exposed alongside encrypted records, enabling unauthorized web crawling and decryption.

The breach exposed the email addresses, evaluation notes, and 200-character idea summaries of 5,000 successful project applicants. Analysis of system logs since May 12 showed no additional leaks. The NIS traced 39 domestic IP addresses attempting access, which police are currently investigating for potential links to local artificial intelligence solution firms.

In response, the ministry has revamped its platform infrastructure. Unnecessary API functions were removed, database encryption was upgraded, and automated web crawling protections were strengthened. Privacy policies were also tightened: user data will now be purged immediately upon account deletion, while applicant records will be held for five years. Startup ideas are now designated as sensitive data with restricted access.

Relief efforts have supported nearly 1,000 concepts through 785 trade secret certifications and 232 idea deposits. Comprehensive security evaluations by government bodies, including the NIS and Personal Information Protection Commission, are scheduled for completion by mid-August. The ministry confirmed it will retain the current platform operator to avoid a five-month redevelopment delay, aiming to launch the project's second cohort immediately after security fixes are finalized.

WEEKLY HOT