SMEs and Startups Ministry Data Leak Exposes 5,000 Emails and Ideas

Data Breach Involving Startup Competition Participants
A significant data breach has been reported involving the personal information of 5,000 first-round qualifiers in the national startup competition "Startup for All," organized by the Ministry of SMEs and Startups. The leaked data includes email addresses, summaries of business ideas, and evaluation comments. While no confirmed cases of real names, mobile phone numbers, or detailed business proposals have been disclosed, the incident has prompted an emergency security review to assess the full extent of the breach.
Timeline of the Incident
The breach was first detected on the morning of the 15th at 9 a.m., when the profiles of the 5,000 participants were made publicly accessible on the competition's website. Although nicknames were visible, participants had the option to keep their email addresses and self-introductions private. Despite these privacy settings, unauthorized attempts to access non-public details followed the profile disclosure.
The Ministry of SMEs and Startups became aware of the anomalies around 3 p.m. that day through user inquiries posted on the platform. They took immediate action by blocking unauthorized access routes at 4 p.m. On the following day, the 16th, a complaint was received from a participant who claimed to have received a promotional email from an AI solution company using their non-publicly registered email address.
Investigation and Security Measures
An investigation revealed that the breach occurred through 9 IP addresses. The affected data included email addresses, summaries of ideas, and evaluation comments. However, no evidence has been found that real names, mobile phone numbers, or detailed business ideas were accessed or leaked.
Following the initial detection of the breach at 4 p.m. on the 15th, the Ministry of SMEs and Startups blocked all access routes. On the evening of the 16th at 6 p.m., additional security measures were introduced to prevent external AI-based automated data collection. An emergency security inspection is currently underway across the entire system to determine if further leaks occurred and to trace how the information was used.
Response and Communication
Notifications to affected individuals were issued at noon on the 18th, three days after the incident. The Ministry of SMEs and Startups individually informed the victims and posted an announcement on the platform. At 1 p.m. the same day, the agency reported the breach to the Korea Internet & Security Agency (KISA) and established a victim support center. It is also collaborating with external institutions, including the National Cyber Security Center, to investigate and analyze the security incident.
Statement from Officials
A representative from the Ministry of SMEs and Startups stated, “We recognize the gravity of this incident and will swiftly implement all necessary measures to protect victims and prevent further damage. We will continue to strengthen our personal information protection and security management systems.”
Additional Information
For those interested in membership options, there are several plans available:
- A monthly membership plan priced at 5,900 won, offering reduced rates for newspaper readers at 2,900 won.
- A subscription plan worth 55,000 won, providing access to 8 different newspapers and magazines.
- A membership plan that includes 7,000 points, which can be used like cash for shopping.