South Korean Diplomat Training System Breached, Personal Data Stolen
Hackers accessed South Korea's Ministry of Foreign Affairs' online education system for nine months, exfiltrating personal data of current and former employees.

Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs. The breach of the Korea National Diplomatic Academy's e-learning platform occurred over a nine-month period, from April 2025 to February 2026, before a related government authority alerted the ministry to abnormal system access.
In response to the discovery, the Ministry of Foreign Affairs (MoFA) immediately shut down the affected system and has not yet restored its functionality. The compromised data is believed to include employee IDs, names, email addresses, and encrypted passwords. The ministry assured that sensitive information such as contact details and personal photos were not affected by the intrusion.
According to reports, the attackers exploited a previously unknown zero-day vulnerability in the server software, exacerbated by misconfigured security settings, to gain unauthorized access. The ministry noted that the lack of an available security update at the time of the exploit significantly limited their ability to respond effectively.
The Korea National Diplomatic Academy serves as a crucial training ground for diplomatic service candidates, diplomats preparing for overseas assignments, and senior officials from various government branches. The wide-ranging user base of this platform has raised concerns among lawmakers and security analysts regarding the potential scope of the data exposure.
Officials have stated that they are still working to determine the precise nature and extent of the information that was accessed or exfiltrated during the nine-month compromise period. The ministry acknowledged the growing sophistication and expanding reach of cyberattacks as a serious concern and pledged to enhance its internal security systems in collaboration with relevant authorities.
While South Korea frequently attributes cyberattacks on its public institutions to North Korea, the ministry has not yet attributed this specific incident to any particular threat actor. This breach adds to a growing list of high-profile data incidents that are intensifying pressure on Seoul to overhaul its digital security strategies.
This incident follows a significant data breach at e-commerce giant Coupang, which resulted in a record fine of $409 million after exposing approximately 33.7 million customer accounts. These events have contributed to a substantial rewrite of South Korea’s Personal Information Protection Act, set to take effect in September, which imposes stricter penalties and designates CEOs as ultimately responsible for data protection compliance.
The ongoing cybersecurity challenges underscore the critical need for robust security measures in government training platforms and the broader public sector, especially as threat actors continue to leverage sophisticated techniques to exploit vulnerabilities.
The breach, which began in April 2025, was only disclosed in July 2026, with South Korean officials citing the sensitive nature of diplomatic affairs as the reason for the delay. While the initial disclosure mentioned personal data of current and former Ministry of Foreign Affairs employees, including overseas diplomats, was exfiltrated, the new report clarifies that the compromised system was an online education platform used for remote training and video-conferencing, and that the data leak occurred between April 2025 and February 2026, impacting at least 6,000 individuals.
The new article provides further details on the breach, specifying that the attackers exploited a server-side vulnerability in the online education platform between April 2025 and February 2026. It also clarifies that while user IDs, names, emails, and encrypted passwords were exposed, highly sensitive personal information such as national identification numbers and home addresses were not compromised, mitigating some of the risks associated with identity theft.
The breach, which lasted from April 2025 to February 2026, exploited a zero-day vulnerability, according to the ministry. While officials have not attributed the attack, security researchers note that such exploits against third-party software are consistent with tactics used by North Korean state-backed hacking groups. The ministry delayed its public announcement by five months due to the sensitivity of diplomatic and security affairs and the need for thorough investigation.