South Korean Diplomatic Academy Hacked: Personal Data of Foreign Ministry Employees Compromised
An online education system used by South Korea's **Korea National Diplomatic Academy** has been compromised, leading to the theft of personal information belonging to current and former employees of the Ministry of Foreign Affairs. The breach, which exploited a zero-day vulnerability and misconfigured security settings, went undetected for nearly a year, raising significant concerns about the scope of exposure and the nation's cybersecurity posture.
# South Korean Diplomatic Academy Hacked: Personal Data of Foreign Ministry Employees Compromised
Unidentified hackers have successfully breached an online education system operated by South Korea's **Korea National Diplomatic Academy**, resulting in the theft of personal information belonging to current and former employees of the country's **Ministry of Foreign Affairs** (**MoFA**).
## Long-Term Compromise Uncovered
The **MoFA** announced on Monday that the breach of the academy's e-learning platform occurred between April 2025 and February 2026. The compromise was only brought to light when a related government authority notified the ministry of abnormal access to the system.
Upon discovery, the ministry immediately shut down the affected system, which has remained offline since.
## Data Exfiltrated
Compromised data is believed to include the ID, name, email, and encrypted password of trainees. The ministry clarified that more sensitive information, such as contact details and personal photos, was not affected.
According to the **JoongAng Daily** newspaper, the attackers exploited a previously unknown zero-day vulnerability within the server software. This was compounded by misconfigured security settings, which facilitated access to the network.
βNo security update was available at the time, which limited our ability to respond,β the ministry stated, highlighting the challenges posed by zero-day exploits.
## Broad Impact and Growing Concerns
The **Korea National Diplomatic Academy** plays a crucial role in training diplomatic service candidates, diplomats preparing for overseas postings, and senior officials from various central and local government bodies. The extensive user base has prompted lawmakers and security analysts to express significant concern regarding the potential scope of the exposure.
The ministry has yet to precisely determine what information was accessed or exfiltrated during the nearly year-long period of compromise.
βWe view the growing sophistication and expanding scope of cyberattacks as a matter of serious concern,β the **MoFA** commented, affirming its commitment to strengthening internal security systems in collaboration with relevant authorities.
## Attribution and Broader Context
The ministry has not attributed the attack to any specific threat actor. However, South Korea has historically attributed the majority of cyberattacks targeting its public institutions to North Korea. The **National Intelligence Service** has previously estimated that North Korean actors are responsible for approximately 80% of attacks aimed at the South Korean government sector.
This incident is the latest in a series of high-profile data breaches that have increased pressure on Seoul to overhaul its digital security strategies. In June, South Korea's data protection regulator imposed a record fine of $409 million against e-commerce giant **Coupang** following a 2025 incident that exposed roughly 33.7 million customer accounts, affecting approximately 65% of the nation's population.
These incidents have been a catalyst for a landmark rewrite of South Koreaβs **Personal Information Protection Act**, which is scheduled to take effect in September. The amended legislation will allow for fines of up to 10% of a companyβs turnover for data breaches and explicitly designates the CEO as ultimately responsible for data protection compliance.