Encryption Key Exposure via API Leaks Personal Data of 5,000 South Korean Startup Applicants
What Happened — In July 2026 the government‑backed South Korean startup platform Modu‑ui Changup suffered a breach. An encryption key was hard‑coded into an API response, allowing an external crawler to retrieve the key together with encrypted applicant data. The leak exposed email addresses, evaluation comments, and summaries of startup ideas for roughly 5,000 successful applicants.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a control gap that SOC 2 Continuous Compliance programs are built to detect, document, and remediate (encryption‑key management, CC6.1).
- Continuous evidence collection and control‑mapping tools can provide auditors with a defensible trail showing that keys are stored in a managed KMS, rotated regularly, and never hard‑coded.
- Verisq’s Control Mapping capability lets you map key‑management controls to SOC 2 criteria and automatically capture evidence for audit readiness.
Who Is Affected — SaaS platforms handling personal data, government‑backed innovation programs, and any organization that stores encrypted PII.
Recommended Actions
- Conduct an immediate inventory of all encryption keys and verify none are embedded in code, config files, or API payloads.
- Migrate keys to a dedicated Key Management Service (KMS) or HSM and enforce strict access controls (SOC 2 CC6.1).
- Update your SOC 2 control documentation, map the key‑management process, and begin continuous evidence collection to demonstrate compliance.
Technical Notes – The breach stemmed from a misconfiguration: hard‑coded encryption keys were returned via an API endpoint. No CVE is associated; the exposure was due to insecure key handling rather than a software flaw. Source: BleepingComputer