The record
Written from the 1 report below. Nothing here is unsourced.
- South Korea has disclosed a data breach in which hackers accessed the National Diplomatic Academy's online education system for about ten months, from April 2025 to February 2026, stealing personal information of at least 6,000 current and former Foreign Ministry employees and diplomats, including 350 government attachés posted abroad.
- The leaked data reportedly includes names, IDs, email addresses, and encrypted passwords, though the ministry says sensitive details like home addresses and phone numbers were not exposed.
- The breach went undetected for months partly because the compromised server sat inside the ministry's headquarters and was excluded from regular security checks, and the ministry disclosed the incident five months after discovering it, citing the sensitivity of diplomatic and security affairs.
What to watch next
- Korean media reports suggest the number of affected individuals could be as high as 10,000 and that job titles and department affiliations were also exposed, so the official impact figures may be revised.
- The breach was discovered by the National Intelligence Service rather than the ministry itself, which may prompt scrutiny of why the server was excluded from regular security monitoring.
- Watch for any follow-up on the identity of the unknown threat actor and whether the stolen diplomat information is used in targeted phishing or espionage-related activity.
Coverage1
1 report
International1
All filed from United States
Named South Korea · Diplomats · Ministry of Foreign Affairs · National Diplomatic Academy · National Intelligence Service · Park Il · Unknown threat actor
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
