A recent data breach in South Korea's government-backed startup support platform, Modu-ui Changup, has exposed the personal information of approximately 5,000 successful applicants. The incident occurred in July and was caused by a critical encryption key management failure, highlighting the importance of proper encryption key protection.
Background of the Breach
The platform, which supports a nationwide startup audition program overseen by South Korea's Ministry of SMEs and Startups, stores participants' personal information, including startup ideas, email addresses, and names. One month prior to the reported breach, concerns had been raised that applicants' personal information could be structured and exposed through API responses within the platform.
The government stated that it took immediate action, but did not disclose whether it had improved the platform's underlying security architecture. On June 18, the Ministry of SMEs and Startups announced that personal information and summaries of startup ideas had been leaked, and subsequently launched a detailed investigation together with the National Intelligence Service, the Cyber Security Center, and the National Police Agency.
How the Breach Occurred
On July 31, authorities confirmed that the decisive cause of the personal information and startup idea leak was the exposure of an encryption key through an API. The leaked data had already been encrypted; however, the encryption key was exposed together with the API data, resulting in the disclosure of email addresses, evaluation comments, and startup idea summaries belonging to about 5,000 successful applicants.
The Ministry of SMEs and Startups explained that the encryption key had been included within the API, and an external party collected API data through methods such as web crawling, which led to the exposure of the key. This case illustrates the risks of hard-coding encryption keys as fixed values within application code, configuration files, databases, or similar environments.
Consequences and Lessons Learned
Authorities identified 39 IP addresses involved in accessing the leaked information, all of which originated in South Korea. They also stated that investigations were continuing into further details, including possible connections to AI solution providers.
When an encryption key becomes externally exposed, simply revoking the compromised key and issuing a new one is not enough. Organizations must also re-encrypt all existing data protected by the compromised key and analyze key access logs to determine the full scope of the breach. In addition, they need to reassess access permissions across APIs, servers, and internal storage systems, and notify affected data subjects.
Importance of Encryption Key Management
Encryption alone provides little meaningful protection if an organization does not separate encryption keys from the data they protect. Without secure encryption key management, encrypted information remains exposed. If an encryption key is compromised, an attacker may gain the ability to access data within the system in real-time.
Organizations should store encryption keys in a dedicated Key Management System (KMS) that remains physically or logically separated from databases and applications. Applications should request access to a key from the KMS only when they need to read or process protected data, and should not store the key themselves.
Encryption is essential for meeting regulatory requirements such as the GDPR, Cyber Resilience Act (CRA), and HIPAA. However, inadequate key management can allow encrypted data to be decrypted immediately after a key is compromised, undermining the effectiveness of encryption and preventing organizations from achieving the intended level of regulatory compliance.
Effective Protection with D.AMO Key Management
D.AMO, Penta Security's data security platform, provides encryption-based data protection together with secure key management and access control, backed by nearly 30 years of cybersecurity expertise. D.AMO provides integrated encryption, access control, backup, and recovery capabilities across an organization's entire infrastructure, including both on-premises and cloud environments.
The D.AMO Key Management System (D.AMO KMS) physically and logically separates encryption and decryption keys from the data they protect, and manages the entire key lifecycle, enabling organizations to quickly investigate key-related activity when a security incident occurs.
If D.AMO had been implemented on the South Korean government startup platform, the data breach caused by inadequate encryption key management could have been prevented. Enterprises and public institutions need to shift their approach to data security from post-incident response to proactive prevention, protecting sensitive data with both strong encryption and secure, centralized encryption key management.
Complete Data Security. Flawless Key Management. Powered by 30 years of expertise, D.AMO delivers complete data protection and bulletproof key management.
Source: BleepingComputer