Security Tightened After 'Everyone's Startup' Also Exposed Its Encryption Key
- Input
- 2026-07-31 15:26:18
- Updated
- 2026-07-31 15:26:18

It was also found that the encryption key stored in the API was leaked as well.
The Ministry of SMEs and Startups said on the 31st that it held a briefing at the Government Complex Seoul, chaired by First Vice Minister Noh Yong-seok, on the progress of the 'Everyone's Startup project information leak and future plans.'
The MSS said it carried out a full overhaul of the system after reviewing the cause of the leak and the platform as a whole, based on security vulnerabilities identified by the National Intelligence Service and improvements to personal information management systems diagnosed by an outside security firm.
The investigation found that a total of 39 domestic IP addresses attempted to access the API containing private information.
As a result, the email addresses, review comments and startup idea summaries of 5,000 selected participants in Everyone's Startup were leaked.
Although the leaked information was encrypted, it was confirmed that decryption was possible because the encryption key, which had been included in source code form, was leaked along with it.
Details on the IP addresses and any links to artificial intelligence solution providers are under investigation by the National Police Agency.
To address the problems, the MSS decided to minimize the amount of information stored in the API and require additional verification by security specialists whenever new programs are built.
It will also introduce a new encryption solution to protect the database and strengthen the encryption system for personal information. In addition, all access to the API will be recorded in system logs, and blocking functions against web crawling attempts will be upgraded. Web crawling refers to an AI-based automated collection method, which was the technique used by the company behind this leak.
At the briefing, Vice Minister Noh said, "The encryption key should have been managed separately, but it was stored inside the API," adding, "We have completed full corrective measures for the identified security vulnerabilities and improvements to the personal information management system this month, and each measure is being verified by outside security experts to ensure objectivity."
The ministry will also revise the personal information management system, which has been criticized for keeping data longer than standard practice and collecting too much information.
First, it will separately manage personal information that had previously been retained for five years after membership withdrawal, depending on the type of user. For regular members, personal information will be destroyed immediately upon withdrawal.
In particular, the ministry will include the 'idea application form' in the scope of personal information management and treat startup ideas as important information equivalent to personal data.
Access rights to sensitive information, including personal data, will be redesigned so that no administrators other than the minimum number of authorized personnel can view it.
The ministry will also support idea protection measures and consulting services for users worried about leaks of their startup ideas, while operating a damage reporting center.
To restore trust in Everyone's Startup, the MSS plans to consult with relevant ministries and agencies, including the NIS, the Ministry of the Interior and Safety and the Personal Information Protection Commission, and complete the administrative procedures required for public information systems by the middle of next month.
Vice Minister Noh stressed, "We will carry out the security reinforcement measures without delay and turn the 'Everyone's Startup platform' into an integrated gateway for entrepreneurial challenges that the public can trust again."
[email protected] Kim Hyun-cheol Reporter