South Korea revealed that hackers infiltrated the Nationwide Diplomatic Academy’s on-line training system for 10 months and stole private info of present and former Ministry of Overseas Affairs (MFA) officers, together with diplomats abroad.
The incident occurred in April 2025 after an unknown attacker exploited a vulnerability within the Academy’s servers. No less than 6,000 individuals are affected, together with 350 present authorities attachés posted abroad.
The training platform was established in 2022 to help distant coaching throughout the COVID-19 pandemic and has since been used for presidency worker coaching and video conferencing.
10 months of hacker entry
In response to the announcement, the information was leaked from April 2025 to February 2026.
The South Korean authorities introduced, “From April 2025 to February 2026, the private info of present and former staff and different staff of the Ministry of Overseas Affairs and its abroad diplomatic missions was leaked.”
It’s estimated that the leaked info consists of IDs, names, e-mail addresses, and encrypted passwords of people registered within the training system.
The MFA mentioned the incident didn’t reveal any distinctive identification numbers, delicate info, cell phone numbers, pictures or residence addresses.
The ministry has blocked entry to on-line training methods and carried out extra measures to strengthen safety.
At a press convention right now, an MFA spokesperson mentioned the ministry had delayed making the case public attributable to its delicate nature and the necessity to totally analyze and think about the matter earlier than making it public.
“We have been conscious of this difficulty in February, however because of the sensitivity of the problem relating to our nation’s overseas and safety points and the necessity for cautious consideration and evaluation, we introduced it 5 months later,” mentioned Park Il, spokesperson for the South Korean Ministry of Overseas Affairs.
Doubtlessly affected people are inspired to be alert to any suspicious communications and instantly report them to the Division’s Safety Division.
MFA warns, “Be particularly cautious when receiving e-mail from unclear or unknown sources.”
South Korean media have reported that the variety of folks affected may attain 10,000, however different sources report decrease numbers. He additionally identified that his official title and division had been uncovered.
One purpose the hack went undetected for therefore lengthy is reportedly as a result of the compromised server was situated inside MFA headquarters and was excluded from common safety monitoring.
The identical report states that the breach was found by the Nationwide Intelligence Service in February 2026, and that the intelligence group alerted MFA to the breach.
Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remainder strikes invisibly via the surroundings.
Picus’ whitepaper exhibits the right way to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
