The 'Everyone's Startup' project, a key government initiative, experienced a data breach due to the exposure of an API key necessary for data decryption. Despite the data being encrypted, the key was accessible through external collection methods, compromising sensitive information of 5,000 successful applicants.
On July 31, Noh Yong-seok, the acting Minister of SMEs and Startups, held a briefing at the Government Seoul Complex, announcing the findings of an investigation conducted in collaboration with the National Intelligence Service and the Personal Information Protection Commission.
According to the government investigation, the breach occurred when non-public information was included in certain APIs within the 'Everyone's Startup' platform. This information was leaked during the API collection process, which involved web crawling by external entities.
The core issue was the compromise of the encryption system. Although the leaked data was encrypted, the API collection process also exposed the decryption key, allowing external parties to access the information directly.
The leaked information included email addresses, evaluation comments, and summaries of startup ideas within 200 characters for the 5,000 successful applicants.
It was confirmed that a total of 39 domestic IP addresses attempted to access the API containing non-public information. Following a police request for investigation on June 22, authorities are examining the detailed IP records, connections to AI solution companies, and the purpose of the leak.
In response to the incident, the Ministry of SMEs and Startups activated a task force immediately after the breach, focusing on protecting applicants and enhancing platform security. To alleviate concerns about idea theft, the ministry began accepting applications for idea protection measures on July 1, resulting in support for over 1,000 ideas, including 785 for 'trade secret original certification' and 232 for 'idea custody.'
The trade secret original certification includes a three-year extension and a fee waiver (50,000 won), while idea custody offers free support for technology custody (300,000 won) if technology is advanced within three years. The damage reporting center has received a total of 87 reports (50 damage reports and 9 requests for confirmation of leaks), with no additional reports received since July 8.
The security system has undergone significant changes. A new encryption solution has been implemented to protect the platform's database, and access to sensitive information has been restricted to a minimal number of top-level personnel. Following these measures, users must now log in after registration to access key information.
However, the Ministry of SMEs and Startups has stated that it will not change the platform operator, citing that a change would require a complete system rebuild, delaying preparations for the second phase of the project.
Noh Yong-seok indicated that the schedule for the second phase will proceed after security reviews by the National Intelligence Service are completed in mid-August.
Noh noted, "We have confirmed strong demand for a quick resumption of the project during meetings with 17 cities and provinces. This project is funded through a supplementary budget, so it cannot be postponed into the next year due to budgetary constraints. We will proceed with the second phase without delay."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
