
Unidentified hackers compromised an online training system used by South Korea’s diplomatic academy, extracting personal data belonging to approximately 10,000 current and former diplomats and ministry staff over a 10-month period, the Ministry of Foreign Affairs disclosed July 20.
The breach targeted the Korea National Diplomatic Academy’s e-learning platform, which was launched in 2022 to provide remote job training and language courses for diplomatic personnel. According to the ministry, attackers exploited a zero-day vulnerability in third-party software running on the platform, gaining access from April 2025 through February 2026. A related government authority eventually notified the ministry of abnormal system access, ending the intrusion.
The exposed data includes usernames, full names, email addresses, and encrypted passwords tied to accounts on the training platform. The ministry said resident registration numbers, the Korean equivalent of Social Security numbers, phone numbers, home addresses, and photographs were not compromised. South Korean daily Dong-A Ilbo reported that personal information belonging to roughly 10,000 individuals may have been affected, including personnel stationed at embassies and consulates abroad.
The ministry acknowledged it discovered the breach in February 2026 but waited five months before going public. Foreign Ministry spokesperson Park Il explained the delay at a press briefing, citing “the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis.” Another official said the delay stemmed from the technical complexity of the investigation and the need to coordinate with other government agencies, not unrelated diplomatic developments.
Security researchers noted that the use of zero-day exploits against third-party software is consistent with tactics previously linked to North Korean state-backed hacking groups. South Korean officials have not formally attributed the attack, and technical analysis remains ongoing.
The ministry has taken the affected system offline and is implementing additional security measures. It warned current and former staff to “exercise special caution when receiving emails from unknown sources,” suggesting the stolen data could be used for targeted phishing against diplomatic personnel.
Sources: Months-long breach exposes South Korean diplomats’ personal data (Help Net Security, Jul 23, 2026); Hackers were inside South Korea’s diplomat training system for 9 months (The Record, Jul 20, 2026); Hacker breaches South Korean database of nearly all diplomats (Bloomberg, Jul 21, 2026)

