South Korean Startup Suffers Breach Due to Encryption Management Failure


Modu-ui, a South Korean government backed startup support platform, suffered a data breach in July. The breach later disclosed a critical encoding key management compromise, showing how encoded information can still become vulnerable when enterprises can’t protect encoding keys properly. 

About Modu-ui

Modu-ui stores participants’ personal details such as email addresses, names, and startup ideas, and the platform also supports a nationwide startup audition overseen by SMEs and Startups (MSS) of the South Korean Ministry.

Suspicions were already raised a month prior to the reported data breach that applicants’ personal data could be structured and exposed via API responses inside the platform. The government said it had taken prompt action but did not reveal if it had upgraded Modu-ui’s security infrastructure.

Startup details leaked

In June, the Ministry of SMEs and Startups disclosed that summaries of startup ideas and personal details had been exposed. Later, it started a detailed enquiry along with National Police Agency, National Intelligence Service, and the Cyber Security Center.

In July, the agencies confirmed that the leak of encoding keys via an API was the reason for the startup idea and personal data leak.

About the breach

The exposed data had already been encoded but the encoded data needs an encoding key decoding.

In this case, the encoding key was leaked along with the API data, causing in the leak of evaluation comments, startup idea summaries and email addresses related to 5000 successful applicants. 

According to the Ministry, the encoding key had been included inside the API and a third party retrieved API data via methods like web crawling, causing the exposure of the key.

Private email addresses were not shown on the public-facing interface but officials believed they could be retrieved via AI-based web crawling. 

Impact on organizations

The incidents also demonstrate the dangers of hard-coding encoding keys as fixed values inside databases, application code, similar environments, or databases.

When businesses follow this method, the keys can become vulnerable in addition to the data or systems they are meant to protect. The main reason for this incident can be viewed as security infrastructure failure in incorporating  robust encoding key management.

Officials found 39 IP addresses related to the access of the exposed data coming from South Korea. Authorities also said that investigations led to more details such as potential connections to AI solution providers.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: