DistantNews
Support us
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Technology

'Modu's Startup' Hacker Identified as Business Support Firm; Stolen Data Used for Promotion

From Hankyoreh · () Korean

Translated from Korean, summarized and contextualized by DistantNews.

At a glance

News Sources not specified Outcome reported
  • A South Korean government program 'Modu's Startup' was hacked, leaking the personal information of 5,000 participants.
  • The hack was carried out by a business support company providing AI solutions, not an external hacker.
  • The company used the stolen information to send promotional emails to participants.

A data breach affecting the South Korean government's 'Modu's Startup' program has been attributed not to an external hacker, but to a business support company that was providing AI solutions to participants. The incident resulted in the leak of personal information, including emails, ideas, and evaluation comments, belonging to 5,000 individuals.

According to a report submitted by the Korea Institute of Startup & Entrepreneurship Development (KISED) to lawmaker Kang Seung-kyu, the AI solutions company obtained the private email addresses of participants through "abnormal application programming interface (API) calls." While these email addresses were not publicly displayed on the website, they were accessible through automated collection methods like AI-based crawling.

The AI solutions company obtained the private email addresses of participants through 'abnormal application programming interface (API) calls.'

โ€” Korea Institute of Startup & Entrepreneurship Development (KISED)Explanation of how the business support company accessed participant data.

The company then exploited the stolen information to send promotional emails to the participants. KISED confirmed that the company "sent promotional emails (for its own company)" using the emails acquired through the hack. This confirmation came after some participants reported receiving unsolicited promotional emails from a specific AI solution provider to their private email addresses.

In response to the breach, a Ministry of SMEs and Startups official stated that the company involved has been removed from the support program's vendor list, as per regulations prohibiting direct promotion to program participants. KISED has announced plans to establish a procedure for victims to verify the data leak and set up a dedicated channel to minimize further damage.

The company sent promotional emails (for its own company) using the emails acquired through the hack.

โ€” Korea Institute of Startup & Entrepreneurship Development (KISED)Confirmation of the misuse of stolen participant data for marketing purposes.
DistantNews Editorial

Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.