< Back to all clusters
[TECHNOLOGY] · South Korea · 2 sources

started · updated

Mira Partners reports personal data leak via MIRA FAAN service

Mira Partners, a back-office service provider for venture capital funds, announced a personal information leak following an unauthorized external attack on its MIRA FAAN service. The breach occurred between August 20 and August 21.

A total of 26 types of information were leaked, including 7 types of personal data: name, email address, phone number, address, detailed address, position, and resident registration numbers. While resident registration numbers were encrypted, the other six categories of personal data were not. Additionally, 19 types of account and history information, such as member IDs and access logs, were compromised.

Mira Partners stated that fund-related data, including investment amounts, ownership ratios, and account numbers, remained secure as they are managed in separate tables. However, concerns remain regarding whether the encryption keys used for resident registration numbers were also compromised, which would allow for decryption.

The company has reported the incident to the Korea Internet & Security Agency (KISA) and the Personal Information Protection Commission. Mira Partners is currently conducting security vulnerability assessments and plans to implement enhanced measures, including web application firewalls (WAF) and anomaly detection systems.

Entities

Korea Internet & Security Agency · Mira FAAN · Mira Partners · Personal Information Protection Commission