South Korea discloses data breach impacting diplomats worldwide

South Korea’s National Diplomatic Academy was breached by hackers for ten months, exposing personal data of 6,000 individuals, including diplomats stationed abroad. The incident occurred when an unknown threat actor exploited a vulnerability in the academy’s server in April 2025 and continued to siphon sensitive information until February 2026.

The compromised online education system, introduced in 2022 as part of remote training efforts during the COVID-19 pandemic, was used for government personnel training and video-conferencing. The leaked data includes names, email addresses, encrypted passwords, and IDs of individuals enrolled in the platform. However, sensitive information such as unique identification numbers, photographs, and home addresses were not exposed.

The breach went undetected for a significant period due to the server’s location within the Ministry of Foreign Affairs (MFA) headquarters, which is typically excluded from regular security scrutiny. It was only discovered by the National Intelligence Service in February 2026, prompting an alert to the MFA about the compromise.

The South Korean government has since blocked access to the online education system and implemented additional security measures to strengthen protection. Potentially affected individuals have been advised to be cautious when receiving emails from unknown sources and to report any suspicious communications immediately to the ministry’s security department.

This incident serves as a reminder of the importance of robust cybersecurity practices, particularly in organizations handling sensitive information. The compromised server’s location within the MFA headquarters highlights the need for thorough assessments and regular security checks to prevent similar breaches. It also underscores the potential consequences of underestimating the threat landscape, where even seemingly secure systems can be vulnerable to exploitation.

For individuals who may have been impacted by this breach, it is crucial to remain vigilant about online security and take proactive steps to protect themselves from potential threats. A simple yet effective measure is to regularly update passwords and enable two-factor authentication whenever possible. Furthermore, being cautious when interacting with unfamiliar emails or attachments can help prevent phishing attacks that often follow data breaches like this one.

In the long run, organizations must prioritize cybersecurity and invest in robust measures to identify vulnerabilities before attackers do. This includes conducting regular penetration testing, implementing incident response plans, and staying informed about emerging threats and technologies. By doing so, they can minimize the risk of similar incidents and protect sensitive information from unauthorized access.


Source: Bleeping Computer — 2026-07-22