Modu’s Startup Personal Data Leak: How Should Victims Respond?

Hello, this is Administrative Agent Jean.
As interest in starting a business has grown, the government launched the “Modu’s Startup” program to identify 5,000 prospective entrepreneurs who have business ideas but are still hesitating to start.
However, on June 15, a personal data leak occurred in “Modu’s Startup,” a public startup audition operated by the Ministry of SMEs and Startups.
External access occurred to the email addresses, idea summaries, and evaluation comments of 5,000 selected applicants, and access through nine IP addresses was confirmed.
I clearly set my information to private, but I received an advertisement at the email address I used for Modu’s Startup.
In fact, some applicants who had not consented to disclosure raised concerns that they received marketing emails at the email addresses they had entered when applying for Modu’s Startup.
Although names and mobile phone numbers were reportedly not leaked, there is other information that deserves closer attention in this case.
That information is idea summaries and evaluation comments.
For prospective entrepreneurs, these may go beyond ordinary personal information and may constitute sensitive information about business ideas and business models.
In this article, I will summarize what victims of the Modu’s Startup data leak can do directly, what personal information dispute mediation is, and how an administrative agent may assist in that process.
Why Is This Personal Data Leak Different From a Typical Email Leak?
“Wasn’t it just email addresses that were leaked?”
You may think so.
But the core issue in this incident is not limited to email addresses.
Personal profiles included public items such as nicknames, follower counts, and whether an applicant advanced to the next round, as well as information that could be set as public or private, including email addresses, idea summaries, and self-introductions.
The particularly important issue is that there were indications that information set to private may also have been externally accessible.
This may be different in nature from a typical shopping mall email address leak.
A prospective founder’s idea summary may include what problem they intend to solve, which customers they target, and how they plan to commercialize the idea.
Evaluation comments may include the strengths and weaknesses of the business model and areas for improvement.
If a third party in a competitive relationship obtains this information, it may create a possibility of secondary harm related to the business idea, beyond simple spam email.
In fact, concerns were raised that a certain company sent advertising emails to selected applicants about “securing R&D grants” and similar services, and that even applicants who had set their information to private received such emails.
Therefore, the important question in this case is not simply:
Was my email leaked?
but rather:
What information was accessible, and how was that information later used?
How Did the Ministry of SMEs and Startups Respond?
The Ministry of SMEs and Startups became aware of the leak through a user inquiry at around 3:00 p.m. on June 15, and blocked the unauthorized access route at around 4:00 p.m.
The next day, June 16 at around 6:00 p.m., it additionally applied a security function to block external AI-based automated collection attempts.
At noon on June 18, it individually notified affected individuals of the personal data leak and reported the incident to the Korea Internet & Security Agency.
In other words, after becoming aware of the incident, the Ministry blocked the access route, implemented additional security measures, notified affected individuals, and filed a report.
But from the victim’s perspective, the problem does not end there.
Even if the institution fixed the security vulnerability, information that has already gone outside and secondary harm resulting from it do not automatically disappear.
Remedies for harm must be considered separately.
What Should Victims Do Immediately?
Step 1 — Block Secondary Harm First
It is advisable to check the password of the email account used for Modu’s Startup and change it if necessary.
If you use the same password for other services, those passwords should also be changed.
You should also pay special attention to emails sent to the leaked email address that mention:
- R&D support
- Government project agency services
- Policy funding support
- Investment attraction
- Startup consulting
- Guaranteed selection for government grants
It is best not to open links or attachments from unclear sources.
You should prepare for the possibility that email addresses obtained through this incident may be used for additional marketing or phishing.
Step 2 — Preserve Evidence First
If you may consider dispute mediation or damages later, you should secure evidence first.
In particular, it is advisable to preserve the following materials separately:
- Personal data leak notification email
- Account information used for Modu’s Startup
- Screens showing public or private settings
- Advertising emails received
- Sender of the advertising emails
- Date and time of receipt
- Full body of the email
- Records of any communication with the company, if any
- Official notices related to the leak incident
If possible, do not stop at screenshots. Preserve the original emails themselves as well.
Screens that were available immediately after the incident may disappear due to platform changes, and emails may also be deleted.
Later, if you want to argue:
I had set my information to private.
After the leak, I received advertising emails from a company I had never heard of before.
you will need materials to support those facts.
Even in personal information disputes, what ultimately matters is showing in documents what happened.
Step 3 — Consider Filing a Personal Information Infringement Report
Victims of personal information infringement may use reporting procedures related to personal information protection.
You can check online reporting procedures related to personal information protection or consultation and reporting procedures by calling 118 without an area code.
The Ministry of SMEs and Startups reporting the leak itself and an individual victim reporting their own harm may have different purposes.
The institution’s leak report is a procedure related to its legal duties as a personal information controller.
By contrast, a victim may separately raise the issue of how their information was leaked and what additional harm occurred.
In particular, if secondary harm such as advertising emails or phishing is confirmed after the leak, it is important to organize those materials together.
What Compensation Procedures Can Personal Data Leak Victims Use?
The main remedies that personal data leak victims may consider can be broadly divided into personal information dispute mediation and civil damages claims.
Among them, personal information dispute mediation is a practical procedure worth considering before going to court.
What Is Personal Information Dispute Mediation?
Personal information dispute mediation is a system designed to resolve disputes arising from the processing of personal information through a mediation procedure without going to litigation.
Applications can be submitted through the Personal Information Dispute Mediation Committee, and victims may also proceed directly.
One advantage is that it can be used without cost burden.
If mediation is successful, it has legal effects provided by law, so it is different from a simple complaint or institutional recommendation.
In personal data leak cases, the facts are usually organized around issues such as:
- What information was leaked
- Whether the applicant had allowed that information to be public
- What contact was received after the leak
- Whether actual secondary harm occurred
- What problems existed in the personal information controller’s management process
Therefore, in dispute mediation, what matters is not just one application form, but what evidence is attached behind it and in what structure.
For example, there is a clear difference between simply submitting only the leak notification email and organizing the materials chronologically as follows:
Private setting screen
→ leak notification
→ advertising email from an external company
→ time of receipt
→ fact that there was no prior business relationship with that company
The latter communicates the facts much more clearly.
Can You Apply for Personal Information Dispute Mediation Against a Public Institution?
Personal information obligations do not apply only to private companies.
Central administrative agencies, local governments, and public institutions may also bear duties to protect personal information when processing it.
Therefore, if harm occurs during the personal information processing of a public institution, personal information dispute mediation may also be considered.
This point is important in the Modu’s Startup incident as well.
The fact that the program was operated by the government does not mean victims cannot seek separate remedies.
Investigation or sanctions against the institution and compensation for victims are separate issues.
Even if the Personal Information Protection Commission later imposes corrective orders, administrative surcharges, or other measures on the relevant institution or contractor, those sanctions are not automatically paid to victims.
Victims must use separate remedy procedures for their own harm.
Does Dispute Mediation Actually Occur in Public Institution Data Leak Cases?
Looking at actual personal information dispute mediation cases, there have been cases involving damages and recurrence-prevention measures related to careless management of personal information by public institutions.
For example, there was a case where a public institution posted materials on its website and a person’s name, phone number, email address, address, work history, and education history became exposed on search portals, raising the issue of emotional distress caused by a personal data leak.
In another case, a request for information disclosure containing the requester’s personal information was shared with multiple departments without de-identification, raising issues of personal information infringement and recurrence-prevention measures.
Dispute mediation cases published by the Personal Information Protection Commission show that personal information exposure can result not only from an employee’s carelessness but also from system management or access permission setting problems.
When compared with the Modu’s Startup incident, the key point to watch is whether the public or private settings matched the actual scope of access.
If a user believed information was private but external access was possible, then the technical and managerial measures taken to protect personal information may become a key issue.
Can a Data Leak Involving Contest Applicants Be Subject to Dispute Mediation?
In personal information dispute mediation cases, leaks of participant information during contests or similar support programs may also become an issue.
In these cases, the analysis does not stop at the fact that:
Personal information went outside.
Other issues may also be examined, such as what kind of personal information it was, how broad the leak was, whether the information was expected to be disclosed externally, and whether actual harm occurred after the incident.
Applicants to Modu’s Startup submitted information related to their business ideas, which makes this different from a typical membership registration data leak.
In particular, if idea summaries or evaluation-related information set to private were also externally accessible, the nature of the harm should be examined individually.
What Is Statutory Damages?
If you suffer harm due to a personal data leak, you may also consider a civil damages claim.
The Personal Information Protection Act contains provisions on damages resulting from personal information infringement.
If the legal requirements are met, there is also a statutory damages system under which a victim may claim damages within a certain range even if they cannot specifically prove the full amount of actual damages.
However, this procedure is litigation through the court.
Representation in litigation and specific legal judgment on damages claims are within the attorney’s role.
An administrative agent cannot represent a party in civil litigation.
Therefore, it is important to distinguish between the dispute mediation stage and the civil litigation stage.
How Are Personal Information Dispute Mediation and Litigation Different?
| Category | Personal Information Dispute Mediation | Damages Lawsuit | |---|---|---| | Institution | Personal Information Dispute Mediation Committee | Court | | Cost burden | Relatively low | Filing fees, service fees, attorney fees may arise | | Procedure | Mediation | Civil litigation | | Core focus | Settlement and dispute resolution | Court judgment | | Application and evidence organization | Important | Important | | Litigation representation | Not applicable | Attorney’s role |
It is not possible to say uniformly which procedure is better.
The answer may depend on the degree of harm, available evidence, whether actual financial damage occurred, and the number of victims.
However, if litigation feels burdensome, it is worth knowing that dispute mediation may be considered as an initial remedy.
How Can an Administrative Agent Help in a Personal Information Dispute?
An administrative agent cannot handle every procedure in a personal information case.
In particular, representation in civil litigation and legal judgment within litigation are the role of an attorney.
However, administrative agent services may be considered in the process of organizing documents and facts to be submitted to administrative agencies or committees.
Preparing a Personal Information Dispute Mediation Application
This involves structurally organizing the circumstances of harm, leaked information, secondary harm, and requested remedies.
Structuring Evidence
Leak notification emails, private setting screens, advertising emails, and dates and times of receipt can be organized chronologically and connected to the application.
Organizing Facts
Even with the same materials, there is a difference between simply attaching multiple files and structuring them in the following order:
Condition before the incident
→ leak incident
→ institutional notification
→ receipt of advertising email
→ harm occurred
It is important to match facts with evidence so that the committee can quickly understand the structure of the case.
Reviewing Follow-Up Dispositions by Administrative Agencies
If investigation or disposition results are issued by the Personal Information Protection Commission or relevant agencies, an administrative agent may assist with organizing those results and preparing documents necessary to consider later available administrative procedures.
How Are the Roles of Administrative Agents and Attorneys Different?
Administrative Agent’s Role
- Preparing documents related to personal information dispute mediation applications
- Organizing the facts of harm
- Structuring evidence
- Preparing documents to be submitted to administrative agencies
- Supporting review of related administrative procedures
Attorney’s Role
- Representation in civil damages lawsuits
- Statutory damages litigation
- Litigation documents and litigation strategy submitted to court
- Attorney-specific work concerning concrete legal disputes
Victims do not necessarily have to file a lawsuit from the beginning.
On the other hand, not every case can be fully resolved through dispute mediation alone.
Therefore, the first step is to identify what stage the harm is currently at.
What Should Victims of the Modu’s Startup Data Leak Do First?
| Order | What to Check | Recommended Timing | |---|---|---| | 1 | Check email account security and block suspicious emails | Immediately | | 2 | Preserve leak notices, advertising emails, and private setting screens | As soon as possible | | 3 | Consider filing a personal information infringement report | After confirming harm | | 4 | Consider whether to apply for personal information dispute mediation | After securing evidence | | 5 | Consider the need for civil damages | Depending on the degree of harm |
The important point is not to delete evidence first.
Especially if you are considering dispute mediation, screens and email records from immediately after the incident may become key materials explaining the case.
As time passes, the platform screen may change, and it may become difficult to reproduce the private setting status as it was at the time.
Therefore, before asserting your harm, it is advisable to first check:
What can I prove right now?
Closing
The most important issue in the Modu’s Startup personal data leak is not merely that email addresses went outside.
The key issue may be the extent to which information that prospective founders chose not to disclose, including idea summaries and evaluation-related information, was accessible.
And even if the Personal Information Protection Commission or relevant agencies investigate the incident, the issue of compensation for individual victims is not automatically resolved.
Victims must separately exercise their own rights.
The first thing to do is to check account security and preserve currently available evidence, such as leak notifications, advertising emails, and private setting screens.
After that, depending on the nature of the harm, you may consider filing a personal information infringement report, applying for dispute mediation, and, if necessary, pursuing civil damages.
In particular, personal information dispute mediation is a remedy with a lower access burden than litigation. Therefore, applicants who experienced actual secondary harm from this incident or believe that private information was externally exposed may consider it.
Even among victims of the same data leak, the arguments to make may differ depending on public/private settings, the type of information leaked, whether advertising emails were actually received, and whether additional harm occurred.
Ultimately, what matters is what evidence you can use to explain your harm.