2026 MSS Everyone’s Startup — 5,000 applicants; encryption keys leaked; vendor retained
Data compromised
Emails, ~200-character idea summaries, and evaluation comments for ~5,000 first-round qualifiers; data was encrypted but encryption key also leaked (MSS/NIS briefing)
Technical writeup
Verified — South Korea’s Ministry of SMEs and Startups confirmed ~5,000 Everyone’s Startup (모두의 창업) first-round qualifier records were exposed. June 2026 notices described partner-side access; a July 31, 2026 MSS briefing (Chosun and other Korean press) said a joint NIS investigation found non-public information in platform APIs scraped via web crawling from 39 domestic IPs (up from 9 initially). Although data was encrypted, the encryption key was also present and leaked, enabling decryption. Suspected perpetrator is an AI solution company participating in the project (Daejeon police booked the representative). MSS said it would not replace the platform operator for phase two—switching would require ~5+ months of redevelopment—and instead hardened APIs, encryption, and abnormal-access blocking. Idea-theft allegations were reported unfounded after investigation.
Root cause
Non-public data exposed via Startup for All platform APIs (web crawling); encryption key also present in API material enabling decryption — partner AI firm under police investigation; operator retained (Jul 31 MSS briefing)
References
- https://m.ajupress.com/amp/20260708181670693
- https://www.chosun.com/english/industry-en/2026/06/18/7BX5FNABMRB6DHV7FKZ64OS76U/
- https://en.sedaily.com/technology/2026/06/21/modus-startup-data-leak-traced-to-participating-firm-not
- https://www.chosun.com/english/industry-en/2026/07/31/3AV3B6AXWJB5RJHLO6NXJZ2NT4/
- https://www.asiae.co.kr/en/article/2026073111584880949