
Han Seong-sook, the Minister of SMEs and Startups who has been nominated as prime minister, bowed in apology Saturday over the personal data leak from the "Startup for All" platform. "As the minister of the responsible ministry, I feel a heavy sense of responsibility," Han said on her way to work that day. "Startup for All" is a government-led startup audition open to all citizens and one of the flagship projects Han planned as minister of SMEs and startups. It is also a core project of the "National Startup Era" policy, which the government has put forward to address the problems of the "K-shaped growth" structure, in which polarization has deepened under the Lee Jae-myung administration. In the government-led startup audition, in which more than 60,000 citizens participated, a final 5,000 were selected, and their non-public information—including emails, business ideas and review comments—was entirely leaked.
The "Startup for All" data leak has severely undermined trust in the government's overall security framework. It is particularly shocking that this leak resulted not from an external attack but from the hacking of a company that supported participants in the project. The fact that a data leak occurred at the hands of a project participant within a platform operated under the government's security management system clearly shows how loosely the security framework of the national public system is managed. Moreover, although users had warned of weak security—citing excessive exposure of participants' non-public information—from a month before the incident, the security structure was not improved. This is why some say it was a man-made disaster caused by the government's complacent response.
With the spread of artificial intelligence (AI) and the activation of the data economy, the risk of personal data leaks can only grow larger in the future. There must be heightened alertness, given that the hacking of government-driven projects is ultimately directly linked to the safety of the national security network. A complacent, after-the-fact response cannot block the increasingly sophisticated attacks of hackers armed with AI technology. Taking this incident as an opportunity, the government must conduct a full review of its security management framework and, through joint responses among related departments, firmly plug the holes in the national security network and public institutions' information systems. Last year, Japan roughly doubled the organization and personnel of its National Center of Incident Readiness and Strategy for Cybersecurity. To block attacks by hackers wielding AI technology, the government should also actively consider committing more budget and personnel to security investment.






