South Korea diplomatic academy hack exposes diplomat data

Vlad CONSTANTINESCU

July 23, 2026

South Korea diplomatic academy hack exposes diplomat data

An intrusion lasting nearly 10 months exposed names, emails and encrypted passwords associated with thousands of South Korean officials.

Key takeaways

  • Hackers maintained access to the Korea National Diplomatic Academy’s online education system between April 2025 and February 2026.
  • The breach exposed names, user IDs, email addresses and encrypted passwords of current and former Foreign Ministry personnel.
  • Reports estimate that roughly 6,000 people were affected, while the compromised database may have contained up to 10,000 records.
  • South Korea shut down the platform and warned affected users to treat unexpected emails with particular caution.

Hackers remained inside for nearly 10 months

South Korea’s Ministry of Foreign Affairs has disclosed a prolonged breach of the Korea National Diplomatic Academy’s online training platform. An unidentified attacker exploited a security vulnerability and maintained access from April 2025 until February 2026, when suspicious activity was detected and the system was taken offline.

The platform was introduced in 2022 to support remote training and videoconferencing. Officials waited approximately five months after discovering the compromise to announce it publicly, citing the diplomatic sensitivity and the time needed to investigate the incident.

Exposed records could fuel targeted phishing

Leaked information included user IDs, names, email addresses and encrypted passwords, the ministry said. Korean media reported that job titles and departmental affiliations were included in some records. The exposed data did not include resident registration numbers, phone numbers, home addresses, photographs or other sensitive information, according to the ministry.

Even without financial details, the information could help attackers create convincing spear-phishing messages impersonating colleagues, government departments or trusted services. The ministry has urged affected personnel to be especially cautious with emails from unclear sources and to report suspicious communications immediately.

The attacker remains unidentified

Officials have not publicly attributed the intrusion, and the precise number of affected individuals remains under review because the database may contain duplicate or outdated entries. The Foreign Ministry says it has blocked the platform, strengthened security measures and is working to prevent additional damage.

Data breaches do not need to expose banking information to create lasting risks. Bitdefender Digital Identity Protection can notify users when personal data appears in breaches or on the dark web, while Bitdefender Ultimate Security provides anti-malware, phishing and scam protection that can help detect malicious links and impersonation attempts.

tags


Author


Vlad CONSTANTINESCU

Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like

Bookmarks


loader