South Korean Government Introduces Trade Secret Certification After Startup Program Data Breach
The South Korean Ministry of SMEs and Startups announced on June 22 that it will offer trade secret original certification services to applicants of its "Startup for All" program following a significant data breach. The measure aims to protect the intellectual property of participants after a security vulnerability exposed sensitive information.
First Vice Minister Roh Yong-seok publicly apologized for the incident, which affected 5,000 applicants who had passed the first round of the government-backed startup incubation program. The breach occurred when an AI solutions company participating in the program exploited a flaw in the project’s website, accessing applicants’ email addresses, startup idea summaries, and judges’ evaluation comments.
The "Startup for All" program, launched earlier this year, is an audition-style initiative designed to support emerging businesses. Of the 63,000 initial applicants, 5,000 advanced to the first round, with 1,000 progressing to further stages. The final 100 competitors will vie for up to 1 billion won (US$654,500) in government support.
In response, the ministry pledged to conduct external investigations and security audits to prevent future breaches. The trade secret original certification a legal tool verifying ownership of confidential business information will help applicants establish proof of their ideas in case of disputes.
Source: https://en.yna.co.kr/view/AEN20260622007000320
Startup for All program participants TPRM report: https://www.rankiteo.com/company/mss1357
"id": "mss1782117225",
"linkid": "mss1357",
"type": "Vulnerability",
"date": "6/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '5,000',
'industry': 'Government/Startup Incubation',
'location': 'South Korea',
'name': 'Startup for All program applicants',
'size': '5,000 applicants affected',
'type': 'Government-backed startup incubation '
'program'}],
'attack_vector': 'Exploitation of website vulnerability',
'data_breach': {'number_of_records_exposed': '5,000',
'personally_identifiable_information': 'Email addresses',
'sensitivity_of_data': 'High (trade secrets, evaluations)',
'type_of_data_compromised': 'Email addresses, startup idea '
"summaries, judges' evaluation "
'comments'},
'date_publicly_disclosed': '2024-06-22',
'description': "A security vulnerability in the 'Startup for All' program's "
'website was exploited by an AI solutions company, exposing '
'sensitive information of 5,000 applicants, including email '
"addresses, startup idea summaries, and judges' evaluation "
'comments.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': 'Email addresses, startup idea summaries, '
"judges' evaluation comments",
'systems_affected': 'Startup for All program website'},
'investigation_status': 'Ongoing (external investigations and security '
'audits)',
'lessons_learned': 'Need for stronger security measures to protect sensitive '
'applicant data and intellectual property in '
'government-backed programs.',
'post_incident_analysis': {'corrective_actions': 'Introduction of trade '
'secret original '
'certification services, '
'external investigations, '
'and security audits',
'root_causes': 'Security vulnerability in the '
"program's website"},
'recommendations': 'Implement trade secret original certification services, '
'conduct regular security audits, and enhance website '
'security to prevent future breaches.',
'references': [{'date_accessed': '2024-06-22',
'source': 'South Korean Ministry of SMEs and Startups'}],
'response': {'communication_strategy': 'Public apology by First Vice Minister '
'Roh Yong-seok',
'recovery_measures': 'Introduction of trade secret original '
'certification services',
'remediation_measures': 'External investigations and security '
'audits'},
'threat_actor': 'AI solutions company participating in the program',
'title': 'South Korean Government Startup Program Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Flaw in the project’s website'}