LIVE · cybersecurity feed
Live wire
breach

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]

zeroday.news · 10d ago

South Korea's Ministry of Foreign Affairs (MFA) has confirmed a data breach affecting the National Diplomatic Academy's online education system, leading to the exposure of personal information belonging to current and former employees, including diplomats stationed abroad. The breach, which occurred between April 2025 and February 2026, was attributed to an unknown threat actor exploiting a vulnerability in the Academy's server.

The MFA stated that approximately 6,000 individuals were impacted, with 350 of them being current government attachés serving overseas. However, some reports from Korean media suggest the number of affected individuals could be as high as 10,000. The compromised data includes IDs, names, email addresses, and encrypted passwords of those enrolled in the education system. Official job titles and departmental affiliations were also reportedly exposed.

The MFA clarified that no unique identification numbers, sensitive information, mobile phone numbers, photographs, or home addresses were compromised in the incident. The online education platform, established in 2022 to facilitate remote training during the COVID-19 pandemic, has since been utilized for government personnel training and video conferencing.

The breach remained undetected for ten months, from April 2025 until February 2026, when it was discovered by South Korea's National Intelligence Service, which subsequently alerted the MFA. Reports indicate that the compromised server was located within the MFA's headquarters and was not subjected to regular security scrutiny, which may have contributed to the prolonged undetected access.

The Ministry delayed public disclosure of the incident for five months, making the announcement in July 2026. An MFA spokesperson, Park Il, explained that the delay was due to the sensitive nature of the matter concerning diplomatic and security affairs, requiring thorough review and analysis before public release.

Following the discovery, the MFA has blocked access to the online education system and implemented additional security measures. Potentially affected individuals have been advised to remain vigilant for suspicious communications and to report any such instances to the ministry's security department. The MFA specifically cautioned against emails from unclear or unknown sources.

breachnation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.