South Korea has disclosed a significant data breach, where hackers infiltrated the National Diplomatic Academy’s online education system for nearly 10 months. This breach compromised personal information of current and former Ministry of Foreign Affairs (MFA) officials, including numerous diplomats stationed abroad.
Detected in April 2025, the cyberattack exploited a vulnerability in the Academy’s servers, affecting at least 6,000 individuals, with 350 serving government attachés overseas among those impacted.
The online education platform, launched in 2022 to provide remote training during the COVID-19 pandemic, has been utilized for government employee training and video conferencing ever since.
10 Months of Unauthorized Access
According to a recent announcement, the data was exposed from April 2025 until February 2026.
The South Korean government confirmed, “From April 2025 to February 2026, personal information of current and former employees of the Ministry of Foreign Affairs and its overseas missions was leaked.”
It is estimated that the exposed information includes IDs, names, email addresses, and encrypted passwords of individuals registered in the education system.
The MFA emphasized that no unique identification numbers, sensitive data, personal phone numbers, photographs, or home addresses were compromised during the breach.
In response, the ministry has blocked access to the online education systems and implemented enhanced security measures.
During a press conference, an MFA spokesperson disclosed the reasoning for the delay in publicizing the incident, citing the sensitive nature of the matter and the necessity for a thorough investigation.
“Although we were aware of this breach in February, the intricacies surrounding foreign and security matters warranted careful consideration prior to making the information public,” stated Park Il, spokesperson for the South Korean Ministry of Foreign Affairs.
Individuals potentially affected are advised to remain vigilant for any suspicious communications and to report them to the Department’s Security Division immediately.
The MFA warns, “Exercise caution when receiving emails from unknown or unclear sources.”
Korean media sources have reported varying estimates of the affected individuals, with potential figures reaching up to 10,000, while others have reported lower numbers. The breach also exposed official titles and departments.
One reason for the prolonged undetected breach was that the compromised server was housed within MFA headquarters and was excluded from standard security monitoring protocols.
Reports indicate that the breach was discovered by the National Intelligence Service in February 2026, who subsequently alerted the MFA.
Data indicates that security teams document only 54% of successful cyberattack attempts while issuing warnings on a mere 14%. The remaining attacks often go unnoticed.
Picus’ white paper provides insights on how to test your SIEM and EDR systems during breach and attack simulations to ensure threats are properly detected.
Source: www.bleepingcomputer.com




