started · updated
South Korea's ‘Everyone's Startup’ Data Breach Hits 5,000 Applicants
A security flaw in the government‑run ‘Everyone's Startup’ (모두의 창업) platform allowed unauthorized web‑crawling of its API, exposing personal data of the first‑round 5,000 successful applicants. The leaked information included email addresses, reviewers’ comments and 200‑character summaries of business ideas, and an encryption key was also compromised.
Investigators traced 39 domestic IP addresses that accessed the hidden API. Deputy Minister No Yong‑seok of the Ministry of SMEs and Startups briefed the press, apologised and said the police are conducting a probe. The ministry has ordered a full redesign of the API, introduction of new encryption solutions, stricter access controls, comprehensive logging and automated detection of crawling attempts. Security procedures will be upgraded to public‑information‑system standards by mid‑August, after which a second round of the program, targeting about 10,000 participants and funded with roughly 200 billion won, is expected to launch.
Entities
Everyone's Startup program · Korean police · Ministry of SMEs and Startups (South Korea) · National Intelligence Service (South Korea) · No Yong‑seok