South Korea's Ministry of Foreign Affairs (MFA) has confirmed a data breach affecting the National Diplomatic Academy's online education system, leading to the exposure of personal information belonging to current and former employees, including diplomats stationed abroad. The breach, which occurred between April 2025 and February 2026, was attributed to an unknown threat actor exploiting a vulnerability in the Academy's server.
The MFA stated that approximately 6,000 individuals were impacted, with 350 of them being current government attachés serving overseas. However, some reports from Korean media suggest the number of affected individuals could be as high as 10,000. The compromised data includes IDs, names, email addresses, and encrypted passwords of those enrolled in the education system. Official job titles and departmental affiliations were also reportedly exposed.
The MFA clarified that no unique identification numbers, sensitive information, mobile phone numbers, photographs, or home addresses were compromised in the incident. The online education platform, established in 2022 to facilitate remote training during the COVID-19 pandemic, has since been utilized for government personnel training and video conferencing.
The breach remained undetected for ten months, from April 2025 until February 2026, when it was discovered by South Korea's National Intelligence Service, which subsequently alerted the MFA. Reports indicate that the compromised server was located within the MFA's headquarters and was not subjected to regular security scrutiny, which may have contributed to the prolonged undetected access.
The Ministry delayed public disclosure of the incident for five months, making the announcement in July 2026. An MFA spokesperson, Park Il, explained that the delay was due to the sensitive nature of the matter concerning diplomatic and security affairs, requiring thorough review and analysis before public release.
Following the discovery, the MFA has blocked access to the online education system and implemented additional security measures. Potentially affected individuals have been advised to remain vigilant for suspicious communications and to report any such instances to the ministry's security department. The MFA specifically cautioned against emails from unclear or unknown sources.






