AI & TechBusinessCybersecurityNewswireTechnology

South Korea data breach exposes diplomats globally

Originally published on: July 24, 2026
▼ Summary

– Hackers breached South Korea’s National Diplomatic Academy online education system for ten months, from April 2025 to February 2026, stealing personal data of current and former Ministry of Foreign Affairs employees, including overseas diplomats.
– The breach exploited a server vulnerability in April 2025, affecting at least 6,000 individuals, with 350 being current government attachés abroad.
– Leaked data includes IDs, names, email addresses, and encrypted passwords, but no unique identification numbers, sensitive information, phone numbers, photos, or home addresses.
– The Ministry delayed disclosure for five months due to the breach’s sensitive nature, announcing it only after thorough analysis; the hack went undetected because the compromised server was inside MFA headquarters and excluded from regular security checks.
– Affected individuals are advised to watch for suspicious communications, and the Ministry has blocked the system and implemented additional security measures.

South Korea has confirmed a major cybersecurity breach at its National Diplomatic Academy, where hackers accessed an online education platform for ten months and stole personal data belonging to current and former Ministry of Foreign Affairs (MFA) staff, including diplomats stationed overseas.

The attack began in April 2025, when an unknown threat actor exploited a vulnerability in the Academy’s server. At least 6,000 individuals are affected, among them 350 active government attachés currently deployed abroad. The compromised platform, launched in 2022 to facilitate remote training during the COVID-19 pandemic, has since served as a hub for government personnel education and video conferencing.

According to the official announcement, data was exfiltrated between April 2025 and February 2026. The leaked information includes user IDs, names, email addresses, and encrypted passwords for individuals registered in the system. The MFA emphasized that no unique identification numbers, sensitive data, mobile phone numbers, photographs, or home addresses were exposed.

In response, the ministry has blocked access to the online education system and introduced additional security measures. During a press briefing today, MFA spokesperson Park Il explained the delayed disclosure: “We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis.”

Those potentially impacted are urged to stay vigilant against suspicious communications and report any such activity to the ministry’s security department. “Please exercise particular caution when receiving emails from unclear or unknown sources,” the MFA warned.

Reports from Korean media indicate the number of affected individuals could reach 10,000, while other sources suggest a lower figure. The same reports note that official job titles and departmental affiliations were also exposed. One reason the breach went undetected for so long is that the compromised server was located inside the MFA’s headquarters and was excluded from regular security audits. The breach was ultimately discovered in February 2026 by the National Intelligence Service, which alerted the MFA to the compromise.

(Source: BleepingComputer)

Topics

south korea hack 98% data breach 97% ministry of foreign affairs 95% diplomatic security 92% personal information theft 91% prolonged undetected access 89% vulnerability exploitation 88% government response 87% delayed disclosure 86% national intelligence service 84%