South Korea Discloses Data Breach Impacting Diplomats Worldwide – Veri Sızıntısı

South Korea Discloses Data Breach Impacting Diplomats Worldwide

South Korea has announced that hackers breached the online education system of the National Diplomatic Academy, stealing the personal data of thousands of employees, including diplomats stationed abroad. The attackers reportedly had access to the system for ten months.

A representative image of the cyberattack targeting the South Korean Ministry of Foreign Affairs, leaking diplomat data.

What Happened

The South Korean government has publicly disclosed a major cybersecurity breach that has sent ripples through international diplomatic circles. In a statement by the Ministry of Foreign Affairs (MFA), it was revealed that the online education system of the National Diplomatic Academy was targeted by unknown hackers, resulting in the theft of personal information belonging to current and former ministry employees. The most striking aspect of the breach is that the attackers maintained undetected access to the system for an extended period of ten months. This raises serious questions about the adequacy of the institution's cybersecurity infrastructure and detection mechanisms. According to the government's announcement, the attack began in April 2025 and was only terminated in February 2026. This prolonged access gave the attackers ample opportunity to leisurely examine, copy, and potentially use the data for other purposes. The public disclosure of the incident occurred on July 22, 2026, approximately five months after its detection. The government attributed this delay to the sensitive nature of the matter and diplomatic security concerns, but it has also sparked debate about transparency and timely notification. The targeted platform was established in 2022 to support remote training during the COVID-19 pandemic and has since been actively used for government personnel training and video conferencing. This indicates the platform was not just an educational tool but also played a role in internal government communication, further increasing the potential impact of the breach.

Data Exposed

According to the official statement from the Ministry of Foreign Affairs, the data leaked as a result of the cyberattack includes the IDs (usernames), full names, email addresses, and encrypted passwords of individuals enrolled in the education system. Although the ministry emphasized that the encryption of passwords provides a layer of security, no details were shared about the strength of the encryption algorithm used or the potential for attackers to crack these passwords. If a weak algorithm was used, these passwords could also be at risk. The ministry's statement specifically mentioned that the leak did not include data considered highly sensitive. Accordingly, it was stated that information that could directly threaten personal security, such as national identification numbers, mobile phone numbers, photographs, or home addresses, was not compromised. However, some reports in the Korean media paint a different picture than the official statement. According to these reports, the leaked data also includes employees' official job titles and their departmental affiliations. If this claim is true, the attackers may possess not only identity information but also a valuable organizational chart showing the hierarchy within the ministry and who holds which diplomatic or administrative position. Such information is an extremely valuable resource for targeted spear-phishing attacks or social engineering operations. This situation places the incident in a more alarming position among the recent rise in Data Breach News targeting government institutions.

How the Attack Occurred

The South Korean government and the Ministry of Foreign Affairs have shared very limited information about the technical details of the attack. According to the official statement, an as-yet-unidentified threat actor infiltrated the system in April 2025 by exploiting a vulnerability in the National Diplomatic Academy's server. However, no details were provided about the nature of this security vulnerability, which software or system component it affected, or how the attackers discovered this flaw. A significant clue as to why the attack went unnoticed for such a long period—ten months—can be found in reports from Korean media. These reports allege that the compromised server was located inside the Ministry of Foreign Affairs' main headquarters. However, it is claimed that this server was excluded from the ministry's regular security audits and scans. If this allegation is true, it exposes a critical security oversight. Organizations often focus on external-facing systems, assuming that systems on the internal network are more secure, but this incident serves as proof of how seriously at-risk internal assets can be. The existence of the breach was discovered not by the government itself, but by the country's National Intelligence Service (NIS) in February 2026. It is reported that the NIS alerted the Ministry of Foreign Affairs after detecting the situation, and only after this warning were steps taken to address the breach. This suggests that the ministry's own internal cybersecurity monitoring capabilities were insufficient to detect a leak of this scale.

Who Was Affected

The profile of those affected by the data breach is one of the most significant factors amplifying the incident's severity. According to official statements, at least 6,000 individuals were affected by the leak. The vast majority of these individuals are current and former employees of the Ministry of Foreign Affairs. More importantly, however, the affected individuals include 350 current government attachés serving in embassies and consulates abroad. These diplomats are critical personnel who conduct South Korea's international relations, have access to sensitive information, and are potential targets for foreign intelligence services. The theft of their identity and contact information could leave them vulnerable to targeted cyber-espionage activities and blackmail attempts. Some reports in the Korean media, which differ from the official figures, suggest that the number of affected individuals could be as high as 10,000. Although the government has not confirmed this number, the possibility that the scope of the leak is broader than officially reported increases concerns. The affected individuals are not limited to ministry staff and diplomats. The phrase "other personnel" in the announcement indicates that the data of employees from other government agencies using the education system or third-party individuals collaborating with the ministry may also have been leaked.

What You Can Do

The Ministry of Foreign Affairs has issued a series of recommendations for all current and former employees potentially affected by the breach. The primary purpose of this advice is to prevent the misuse of the stolen information and to raise awareness among staff about potential secondary attacks. If you are or were an employee of this institution, here are the steps you should take:

  • Be Vigilant Against Suspicious Communications: Attackers can use the stolen names, email addresses, and potentially job titles to send highly convincing phishing emails. Be especially cautious of emails that appear to be from the Ministry of Foreign Affairs or another official body, demand urgent action, or ask you to download an attachment or click a link. Carefully check the sender's email address and avoid opening the email if you have the slightest suspicion.
  • Beware of Emails from Unknown Sources: As warned by the ministry, exercise particular caution with emails from unclear or unknown sources. These emails may be aimed at stealing your credentials or infecting your devices with malware.
  • Password Security: Although the leaked passwords were encrypted, it is recommended that you change them immediately if you use the same password on other platforms. In the future, use strong, unique passwords for all your accounts and enable two-factor authentication (2FA) wherever possible.
  • Report Suspicious Activity: If you notice any unusual activity in your account or communication channels, or if you receive a suspicious email, report it immediately to the ministry's security department. An early warning can help prevent greater damage.

What the Company Is Saying

Following the discovery of the data breach, the South Korean Ministry of Foreign Affairs made a series of statements to manage the situation and inform the public. The ministry first confirmed that the breach had occurred and provided information on the types of data affected and the number of potential victims. As a security measure, it announced that access to the online education system of the National Diplomatic Academy, the source of the attack, was immediately blocked and that additional measures were being implemented to strengthen security across the system. At a press briefing held today, MFA spokesperson Park Il responded to questions about why the breach was disclosed to the public five months after its detection in February. Spokesperson Park attributed the delay to the sensitivity of the matter. "We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis before making it public," he stated. This explanation suggests that the government was trying to buy time to assess the potential impact of the incident on national security and to prevent a potential diplomatic crisis. However, this strategy also leaves open the door to criticism, as it meant that the victims spent five months unaware that they were at risk. The ministry warned potentially affected individuals to be cautious of suspicious communications and stressed that such incidents should be reported immediately to the ministry's security department.

Source

https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.