Korean Diplomat Data Breach: Up to 10,000 Records Exposed in Cyberattack

By Jun sungmin Posted : July 21, 2026, 16:16 Updated : July 21, 2026, 16:16

The online education system server of the National Diplomatic Academy, which trains diplomats and senior officials under the Ministry of Foreign Affairs, was hacked from April last year until early February this year, revealing that approximately 10,000 records were stored on the server.


A Ministry official stated on July 21, "About 10,000 data entries were stored in the system." The Ministry announced the breach in a press release the previous day, revealing that an unidentified attacker gained access to the server of the online education system between April and May last year and maintained access until February this year.


The official noted, "Sensitive personal information such as resident registration numbers, mobile phone numbers, and addresses were not stored on the server," adding that there may be some duplicate entries. The Ministry did not specify the number of times the attacker accessed the system, only stating that it occurred frequently.


The system contained information about Ministry headquarters staff, officials at overseas missions, administrative personnel, and attachés. It reportedly included employees' names, IDs, emails, encrypted passwords, as well as their positions and department affiliations.


Historically, the government has only partially disclosed information about high-ranking diplomats during personnel changes through press releases. There has never been a full disclosure of the list of diplomats or the status of personnel at overseas missions, which may have been compromised in this hacking incident.


Since overseas missions employ not only diplomats but also personnel from other departments in information and security, it is likely that information about national intelligence officials was also leaked.


The Ministry official stated that it is difficult to confirm whether all data stored in the education system was leaked, noting that the figure of 10,000 is an upper estimate. The official acknowledged, "We recognize this situation is not unrelated to national security." They also mentioned, "We need to assess whether there are duplicate entries among the 10,000 data points, but we assume that nearly all personnel from the Ministry headquarters are included."


The official added, "Currently, there is insufficient technical analysis to definitively identify the perpetrator, and we are not ruling out any possibilities, including hacking organizations from other countries."


The National Diplomatic Academy's online education system was established during the COVID-19 pandemic in 2022. Security checks have been conducted periodically since the system's launch.


The Ministry explained that the attack exploited a zero-day vulnerability, which was not known to the software manufacturer at the time, allowing the attacker to access the system using legitimate software permissions. This made detection difficult, and there were no security updates available at that time to address the vulnerability.





* This article has been translated by AI.

Copyright ⓒ Aju Press All rights reserved.