South Korea Confirms Cyberattack on Diplomatic Academy, Data of 6,000 Diplomats at Risk

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Breach confirmed: South Korea's Foreign Affairs Ministry disclosed a cyberattack on the Korea National Diplomatic Academy's online education system.
  • Long access: Attackers controlled a server from April-May 2025 until February 2026 via a zero-day vulnerability.
  • Scale reported: Data belonging to about 6,000 current and former diplomats may have been compromised.

South Korea's Foreign Affairs Ministry said on Tuesday that a "significant" amount of data appeared to have been exposed in a cyberattack on the Korea National Diplomatic Academy (KNDA), as authorities examine potential involvement by foreign state-backed hacking groups.

Ministry Confirms Considerable Data Leak

Ministry spokesperson Park Il, cited by Reuters, told a briefing that findings so far suggested a data leak of "considerable scale." The compromised system stored training videos and course administration data, including participants' names and user IDs. 

Local reporting mentioned a ministry official said "sensitive personal data," such as phone numbers, photographs, government IDs, or home addresses, appeared to be unaffected.

Park said no misuse of the leaked data has been confirmed, and that there's currently insufficient technical evidence to identify who was behind the attack. A ministry statement issued Monday disclosed that the IDs, names, emails, and encrypted passwords of the trainees were involved in the leak.

Zero-Day Vulnerability Enabled Prolonged Server Access

The statement said unidentified attackers exploited a previously unknown zero-day, along with security configuration weaknesses, to compromise the KNDA's online education system. 

The attackers gained control of a server between April and May 2025 and remained in control until February 2026, when a government agency flagged suspicious activity, and the system was blocked. 

North Korea-Linked Groups Under Investigation

South Korean daily Dong-A Ilbo, citing government sources, reported that personal information of about 6,000 current and former diplomats and officials from other ministries may have been compromised, including data on diplomats stationed overseas, Reuters said. 

The outlet reported that intelligence authorities are investigating whether a North Korean-linked hacking group could be behind the targeting. Park said the ministry is working with relevant agencies to establish the full scope of the breach and strengthen its internal cybersecurity systems.

In May, North Korean state-backed Kimsuky APT targeted South Korean entities in a campaign that disseminated backdoors such as HelloDoor, httpMalice, MemLoad, httpTroy, AppleSeed, and HappyDoor.

In April, FortiGuard Labs reported that DPRK phishing campaigns execute multi-stage LNK-file attacks targeting organizations in South Korea. One month earlier, the South Korean tax office leaked cryptocurrency assets, with a critical failure leading to a wallet breach.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: