▲ Roh Yong-seok, Acting Minister of SMEs and Startups and 1st Vice Minister, bows his head during a briefing on the details of the data leak incident on the Modoo Startup project and future plans at the Government Complex Seoul in Jongno-gu, Seoul, on the 31st.
A total of 39 domestic IPs were identified as having made abnormal access attempts to the API (Application Programming Interface) of the "Modoo Startup" platform, where the personal information and startup ideas of 5,000 project successful applicants were leaked.
It was found that the encryption keys were stored together in the relevant API without separate isolation measures, resulting in the leakage of both the encryption keys and various personal information.
The Ministry of SMEs and Startups (MSS) announced this during a briefing on the "Modoo Startup Project Data Leak Details and Future Plans" held at the Government Complex Seoul on the 31st, led by 1st Vice Minister Roh Yong-seok.
Previously, the MSS proceeded with a complete overhaul based on the security vulnerabilities analyzed by the National Intelligence Service and the improvements to the personal information management system diagnosed by an external cybersecurity firm, concerning the causes of the Modoo Startup leak and the platform-wide system.
As a result of the investigation, a total of 39 domestic IPs were confirmed to have attempted access to the API containing private information.
Consequently, the email addresses, evaluation reviews, and startup idea summaries of 5,000 successful applicants of Modoo Startup were exposed externally.
Although the leaked information was encrypted, the encryption keys contained within the source code were leaked together, which made "decryption" possible to revert the data back into readable plaintext.
The Korean National Police Agency is currently investigating the specific IP details and their connection to artificial intelligence (AI) solution companies.
To address these issues, the MSS has decided to minimize the information contained in APIs and go through an additional verification step by a cybersecurity specialist firm whenever a new program is built.
In addition, the ministry plans to introduce a new encryption solution to protect the database, strengthen the personal information encryption system, record all access to APIs in system logs, and upgrade blocking functions against web crawling attempts.
"Web crawling" is an AI-based automated collection function, which was the method used by the company responsible for this leak incident.
During the briefing, Vice Minister Roh explained, "It is true that encryption keys should be managed separately, but the encryption keys were located inside the API. Comprehensive measures regarding the identified security vulnerabilities and personal information management system improvements were fully completed within July, and we are ensuring objectivity as each improvement measure is verified by an external security specialist organization."
The personal information management system, which has been criticized for having a personal information retention period longer than typical standards and collecting excessive types of data, is also being overhauled.
First, the criteria will be reorganized to manage personal information—previously retained for "5 years after membership withdrawal"—by classifying it according to the subscriber type.
Accordingly, for general members, the stored personal information will be destroyed immediately upon membership withdrawal.
In particular, "startup idea application forms" will be included in the scope of personal information management so that startup ideas are managed as sensitive information equivalent to personal information.
Access rights to sensitive information such as personal information have been redesigned so that administrators other than the minimum authorized personnel cannot view personal information.
In addition, for users expressing anxiety over the leakage of startup ideas, the ministry will support idea protection measures and consulting, while also operating a damage reporting center.
To secure reliability for Modoo Startup, the MSS plans to fulfill administrative procedures required for public information systems by consulting with related ministries such as the National Intelligence Service, the Ministry of the Interior and Safety, and the Personal Information Protection Commission until the middle of next month.
Vice Minister Roh emphasized, "We will implement the security reinforcement measures without a hitch to make the 'Modoo Startup Platform' an integrated gateway for startup challenges that the public can trust once again."
(Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News