South Korean Diplomats Data Exposed in Months Long Breach
South Korea's Foreign Ministry confirmed that an online training system for its diplomatic academy was breached in a months-long cyberattack, exposing the personal data of thousands of current and former diplomats. A zero-day exploit is cited as the cause.
What Happened
South Korea's Foreign Ministry has publicly disclosed a significant cybersecurity breach targeting the nation's diplomatic corps. According to a statement from the ministry, attackers infiltrated the online education system of the Korea National Diplomatic Academy (KNDA), gaining access to personal data belonging to current and former ministry staff, as well as diplomats stationed abroad. The severity of the incident has raised concerns within national security circles due to the duration of the breach and the sensitive nature of the targeted individuals.
The target of the attack, the online training platform, was initially launched in 2022 to support remote learning during the COVID-19 pandemic. Since then, it has been actively used to deliver important programs such as job training and language courses for diplomatic personnel. This meant the system housed information for a large number of both current and former diplomats.
According to the ministry's findings, the cyberattackers first gained access to the system in April 2025 and remained undetected for approximately ten months, until February 2026. This extended period provided the attackers with a wide window of opportunity to move within the system, collect data, and conceal their activities. Although the breach was detected in February 2026, the public announcement was delayed until July, highlighting the sensitivity of the matter and the complexity of the investigation.
What Data Was Leaked
The Foreign Ministry shared a list of the data types compromised in the cyberattack. The leaked information includes basic credentials associated with the diplomats' accounts on the training platform. This data comprises:
- Usernames: The account names used to log into the platform.
- Names: The full names of the personnel.
- Email addresses: Official or personal email addresses belonging to the diplomats.
- Encrypted Passwords: The encrypted versions of the passwords used by users to access their accounts.
The ministry sought to allay some concerns by emphasizing that the leak did not include more sensitive information. The statement specified that personal data such as resident registration numbers, phone numbers, home addresses, and photos were not affected by this breach. However, the combination of the data that was stolen poses serious risks, especially for high-profile targets like diplomats. Email addresses and names can be used to orchestrate highly convincing spear-phishing attacks. Attackers could use this information to deceive diplomats with fraudulent emails, attempting to gain access to more sensitive information or state networks. Furthermore, the stolen encrypted passwords, if protected by a weak encryption algorithm, could potentially be cracked and converted to plain text. This creates an additional risk if diplomats reused the same password on other platforms.
How Did the Attack Happen
The South Korean Foreign Ministry stated that the attackers used a "zero-day vulnerability" to breach the system. A zero-day vulnerability is a security flaw in software or a system that is unknown to the vendor or, if known, has not yet been patched. Such vulnerabilities give attackers a significant advantage in infiltrating systems undetected, as there is no known defense method.
Security researchers noted that the use of zero-day exploits against third-party software is consistent with tactics previously linked to North Korean state-backed hacking groups. These groups often employ sophisticated and previously unseen methods to compromise their targets. However, South Korean officials have refrained from officially attributing the attack to any specific group or state. The official statement emphasized that the technical analysis to determine who was behind the attack is still ongoing and a definitive conclusion has not been reached.
Who Is Affected
The victims of the data breach are critical personnel who carry out South Korea's diplomatic and foreign relations missions. According to the ministry's announcement, those affected include current and former employees of the Foreign Ministry and diplomats serving in embassies and consulates around the world. It was also noted that data belonging to officials temporarily seconded to the Foreign Ministry from other government agencies may have been compromised.
According to a report by the prominent South Korean newspaper Dong-A Ilbo, it is estimated that the personal information of about 10,000 current and former diplomats and officials may have been affected by the breach. This figure illustrates the potential widespread impact of the incident on South Korea's diplomatic establishment.
What Can You Do
The Foreign Ministry announced that it immediately shut down access to the affected system and has taken it offline. However, the risks for individuals whose data was compromised persist. If you believe you may have been affected by this breach or wish to enhance your digital security in general, it is recommended you take the following steps:
- Practice Good Password Hygiene: Although the leaked passwords were encrypted, if you used that password on other platforms, change it immediately. Password reuse is one of the most common mistakes that allows a breach at one service to compromise your other accounts.
- Be Vigilant Against Phishing Attacks: With your name and email address leaked, the risk of personalized spear-phishing attacks against you has increased. Be extremely cautious when opening emails from unknown sources or those that appear suspicious. Be wary of messages that request personal information or create a sense of urgency.
- Enable Two-Factor Authentication (2FA): Be sure to enable two-factor authentication on your email and other important online accounts. This provides an additional layer of security that prevents unauthorized access to your account even if your password is stolen.
- Follow Official Channels: The South Korean government has warned citizens to "exercise special caution when receiving emails from unknown sources." Individuals with privacy concerns are advised to contact the Foreign Ministry's security department directly.
What the Company Is Saying
The South Korean Foreign Ministry adopted a transparent stance after the incident came to light, disclosing the situation to the public and providing information on the steps being taken. The ministry stated that it immediately took the affected training system offline and is implementing additional security measures to prevent further damage.
During a press briefing, Foreign Ministry spokesperson Park Il answered questions about why the breach announcement was delayed by five months. Park said, "We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis." This statement indicates how seriously the national security dimension of the incident is being taken.
Another official dismissed speculation that the delay was tied to unrelated diplomatic developments. The official stated that the delay was purely a result of the technical complexity of the investigation and the need to coordinate with other government agencies.
Source
https://www.helpnetsecurity.com/2026/07/23/south-korea-diplomatic-academy-data-breach/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.