An online education system used by South Korea's diplomatic academy was compromised by unidentified hackers for nine months, leading to the theft of personal information belonging to current and former employees of the Ministry of Foreign Affairs (MoFA). The breach of the Korea National Diplomatic Academy's e-learning platform occurred between April 2025 and February 2026.
The MoFA confirmed the incident after a government authority notified the ministry of abnormal access to the system. Following the notification, the ministry immediately shut down the affected system, which has not been restored since.
Compromised data is believed to include trainee IDs, names, email addresses, and encrypted passwords. However, the ministry stated that sensitive information such as contact details and personal photos were not affected.
Reports indicate that the attackers exploited a previously unknown zero-day vulnerability in the server software. This was reportedly compounded by misconfigured security settings, which facilitated access to the network. The ministry noted that no security update was available at the time, limiting their ability to respond.
The Korea National Diplomatic Academy provides training for diplomatic service candidates, serving diplomats preparing for overseas postings, and senior officials from various central and local government bodies. The wide range of users has raised concerns among lawmakers and security analysts regarding the potential scope of the data exposure.
The ministry has not yet determined precisely what information was accessed or exfiltrated during the nine-month compromise period. It expressed serious concern about the increasing sophistication and expanding scope of cyberattacks and stated its commitment to strengthening internal security systems in cooperation with relevant authorities.
The MoFA did not attribute the attack to any specific threat actor. In recent years, South Korea has attributed the majority of cyberattacks on its public institutions to North Korea, with the National Intelligence Service previously estimating that North Korean actors are responsible for approximately 80% of attacks targeting the South Korean government sector.
This incident is the latest in a series of high-profile data breaches that have increased pressure on Seoul to reform its approach to digital security. In June, South Korea's data protection regulator imposed a record fine of $409 million on e-commerce giant Coupang following a 2025 incident that exposed roughly 33.7 million customer accounts.
These incidents have contributed to a significant rewrite of South Korea’s Personal Information Protection Act, which is scheduled to take effect in September. The amended law will allow companies to face fines of up to 10% of their turnover for data breaches and explicitly designates the CEO as ultimately responsible for data protection compliance.






