South Korea has disclosed a data breach affecting current and former Ministry of Foreign Affairs employees, including diplomats posted overseas.
Hackers reportedly accessed the National Diplomatic Academy’s online education platform for around 10 months. The attackers exploited a server vulnerability in April 2025 and remained active until February 2026.
The South Korea diplomatic data breach affected at least 6,000 people, according to the Ministry of Foreign Affairs. Around 350 of those individuals are current government attachés working abroad.
Hackers Accessed Diplomatic Training Platform
The National Diplomatic Academy launched the online education system in 2022 to support remote training during the COVID-19 pandemic.
Since then, the platform has supported staff training and video conferencing for government personnel. However, an unknown threat actor exploited a weakness in one of the Academy’s servers in April 2025.
The ministry said the attackers accessed and leaked personal information between April 2025 and February 2026.
South Korean media reports suggest the total number of affected people may be closer to 10,000. However, authorities have not confirmed that higher figure.
Exposed Data Includes Names and Email Addresses
The South Korea diplomatic data breach exposed user IDs, names, email addresses and encrypted passwords belonging to people registered on the education system.
The Ministry of Foreign Affairs said the incident did not expose unique identification numbers, mobile phone numbers, home addresses, photographs or other sensitive information.
Some reports also indicate that official job titles and departmental affiliations may have been included in the compromised data.
Even without highly sensitive records, the exposed details could help attackers create convincing phishing messages. Diplomats and government employees may face an increased risk of targeted social-engineering attempts.
Breach Remained Undetected for Months
South Korea’s National Intelligence Service reportedly discovered the compromise in February 2026 and alerted the Ministry of Foreign Affairs.
The ministry said it delayed the public announcement because of the incident’s sensitive diplomatic and security implications. Officials also needed time to review the breach and assess the affected data.
Reports suggest the compromised server sat inside the ministry’s headquarters and did not receive the same level of regular security scrutiny as other systems. That may have allowed the attackers to remain undetected for an extended period.
Ministry Blocks Platform Access
The Ministry of Foreign Affairs has blocked access to the online education platform and introduced additional security measures.
It has also advised affected individuals to remain alert for suspicious emails and other unexpected communications. Staff should report potentially malicious messages to the ministry’s security department.
The South Korea diplomatic data breach highlights the risks facing government training platforms and internal systems. Even services built for routine administrative work can provide attackers with valuable access to official identities, contact details and organisational information.


0 responses to “South Korea Diplomatic Data Breach Affects Thousands of Officials”