Personal data of all South Korean diplomats believed leaked in 'unprecedented' cyberattack

Some cybersecurity analysts noted the method used in the attack resembles tactics often used by North Korean state-backed hacking groups.

Published Modified

The personal information of nearly all of South Korea's diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an "unprecedented" cyberattack, exposing up to 10,000 administrative and intelligence records.

The data system of the Korea National Diplomatic Academy (KNDA) — an institution affiliated with the Foreign Ministry that develops and runs education and training programs for diplomats and international affairs personnel across government ministries and the public sector — was belatedly revealed to have been breached between April and May of last year, with unauthorized access continuing until early February.


According to the ministry, the online platform was originally established in 2022 to facilitate remote training during the Covid-19 pandemic.

An unidentified threat actor seized control of the academy's server in mid-2025 and maintained intermittent access for roughly ten months before South Korea's National Intelligence Service detected unusual activity and alerted officials.

Although the ministry shut down the platform immediately upon notification,  it did not disclose the breach publicly until Monday.

The roughly 10,000 records exposed contained names, user IDs, email addresses, encrypted passwords, official job titles and department affiliations, a senior Foreign Ministry official familiar with the matter told reporters on Tuesday.

While officials clarified that the 10,000 figure represents individual data entries rather than a confirmed headcount — noting potential duplicates and non-deleted records of former staff — the leak is assumed to cover nearly all active headquarters personnel and overseas posts. 

"The system stored information on our officials posted overseas, foreign service officers and resident officers, administrative staff working at our overseas missions and other personnel," the official said. "We are assuming that nearly all headquarters personnel are included."

The breach represents a national security concern.

The government has disclosed the postings only selectively for senior diplomats, never releasing a full roster of active foreign service officers or mission staff. Because overseas posts regularly include military attachés and intelligence officers dispatched from other agencies, including the Ministry of National Defense or the National Intelligence Service, sensitive national security personnel may also have been exposed.

Foreign Ministry spokesperson Park Il speaks in a press briefing on July 2.

"We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis," Foreign Ministry spokesperson Park Il said in a press briefing in Seoul later Tuesday. 

Addressing speculation over the timing of Monday's disclosure, another Foreign Ministry official rejected any connection to unrelated diplomatic matters — such as the U.S. ambassador's abrupt visit from Washington or an ongoing trade dispute involving a Korean e-commerce company — saying the delay reflected only the technical complexity of the case and the need to coordinate with other agencies.

The intrusion exploited what the ministry described as a "zero-day" vulnerability — a previously unknown flaw that neither the software's maker nor the wider security industry had identified before the attack.

Some cybersecurity analysts noted the method, exploiting zero-day flaws in third-party software, resembles tactics often used by North Korean state-backed hacking groups. Groups operating under Pyongyang’s Reconnaissance General Bureau — including Lazarus, Kimsuky and Andariel — have repeatedly targeted South Korean public institutions and financial systems through supply-chain vulnerabilities.

Seoul officials emphasized that technical analysis remains ongoing and all possibilities remain on the table.

"There is not yet enough technical analysis to determine who is behind the attack," Park added, "but the government is not ruling out any possibility, including hacking organizations backed by other countries."

The foreign minister was briefed on the breach upon detection and ordered a thorough response in cooperation with relevant agencies, another Foreign Ministry official said, adding that the Blue House was also briefed on the case.

Affected staff have so far been notified only through a general notice posted on the ministry's website on Monday, though officials said they are preparing to notify by email those whose addresses remain valid.

The training platform, at edu.mofa.go.kr, remains completely offline, forcing personnel to temporarily attend in-person sessions or utilize a separate government-wide video conferencing system.


BY SEO JI-EUN   [[email protected]]