South Korea has disclosed a major cyberattack on an online training platform used by its diplomatic personnel, potentially exposing the personal and professional information of thousands of current and former officials, including diplomats and government attachés stationed overseas.
TL;DR
- Hackers maintained access to a diplomatic training server for around ten months.
- Reports place the possible impact between 6,000 individuals and roughly 10,000 stored records.
- Names, emails, encrypted passwords, positions and departmental affiliations may have been exposed.
- Officials have not identified the attackers or confirmed misuse of the stolen information.
What Happened In The South Korean Diplomatic Data Breach?
According to BleepingComputer, an unidentified threat actor compromised an online education system operated by the Korea National Diplomatic Academy, an institution affiliated with South Korea’s Ministry of Foreign Affairs.
The attacker is believed to have gained control of the server between April and May 2025 and retained access until February 2026. A government agency detected suspicious activity and notified the ministry, which immediately blocked the platform and has kept it offline.
The system was introduced in 2022 to support remote education and video conferencing. It was used to train diplomatic candidates, officials preparing for overseas postings and personnel from other government departments.
BleepingComputer reported that at least 6,000 people may have been affected, including around 350 government attachés currently posted outside South Korea. Meanwhile, Yonhap reported that the platform contained approximately 10,000 personal data records, representing the maximum possible number of affected entries rather than a confirmed victim count.
What Information Was Exposed?
The compromised records reportedly included names, user IDs, email addresses, encrypted passwords, official positions and departmental affiliations.
South Korea’s Foreign Ministry said national identification numbers, mobile phone numbers, home addresses, photographs and other particularly sensitive personal information did not appear to have been exposed. However, investigators have not yet established exactly how much information the attackers accessed or removed.
The Korea JoongAng Daily reported that the records may cover almost all active Foreign Ministry headquarters personnel and overseas missions, along with former employees and officials temporarily assigned from other agencies.
Such overseas personnel can include military attachés and intelligence officials. This means the exposure of job titles and institutional affiliations could create national security risks even without identification numbers or residential information.
How Did The Attack Remain Undetected?
Yonhap reported that the attacker exploited a previously undisclosed software flaw, commonly known as a zero-day vulnerability.
Reuters said the intrusion also involved security configuration weaknesses. The compromised server was reportedly located inside the Foreign Ministry’s headquarters and had been excluded from some routine security inspections, helping the attacker maintain prolonged access.
“It was difficult to detect the attack through conventional methods as the intruder exploited a previously undisclosed software vulnerability,” a Foreign Ministry official told Yonhap.
Who Was Behind The Attack?
South Korean authorities have not attributed the breach to a specific hacking group.
Reuters reported that officials are examining whether a foreign state-backed threat actor was involved, including the possibility of a North Korea-linked group. However, Foreign Ministry spokesperson Park Il said there was not enough technical evidence to determine who carried out the operation.
Topics for more insights:
“We do not rule out any possibility, including involvement by overseas hacker groups,” a ministry official told Yonhap, describing the incident as a matter with national security implications.
The ministry has advised potentially affected individuals to be cautious of emails from unknown senders and to report suspicious communications. With names, roles and email addresses potentially exposed, the stolen information could support highly targeted phishing or impersonation attempts against diplomatic personnel.




















