South Korea’s Ministry of Foreign Affairs said unidentified hackers broke into the Korea National Diplomatic Academy’s online training platform and remained there for months, exposing account information tied to current and former ministry staff.
The ministry disclosed Monday that the compromise ran from April 2025 until February 2026, when another government authority alerted it to unusual access on the system. The ministry said it took the e-learning platform offline immediately after the warning and has not brought it back into service.
The exposed records are believed to include trainee IDs, names, email addresses and encrypted passwords, according to the ministry’s data protection notice. The ministry said contact information, personal photographs and other “sensitive information” were not affected.
That caveat leaves a large unresolved question. The ministry said it cannot yet say exactly what data the attackers viewed or removed during the intrusion. In other words, officials know the door was open for roughly nine months, but they are still working out what walked through it.
How the attackers got in
JoongAng Daily reported that the attacker used a previously unknown zero-day flaw in server software, with misconfigured security settings worsening the exposure. The foreign ministry said no security patch was available at the time, which limited its response options.
A zero-day vulnerability is a bug the vendor has not yet fixed, often because the vendor does not know about it. That does not make a breach automatic. Configuration mistakes can widen the blast radius by leaving services reachable, weakening access controls or failing to contain a compromised component. The ministry has not published technical indicators or named the affected software.
The Korea National Diplomatic Academy trains diplomatic service candidates, diplomats preparing for overseas assignments and senior officials from central and local government. That user base gives the breach a broader public-sector footprint than a routine school platform compromise, even if the confirmed data set is limited to account details.
No attribution yet
The ministry has not blamed any country or hacking group. That distinction matters. South Korea has repeatedly attributed cyberattacks on public institutions to North Korea, and the National Intelligence Service has previously said North Korean actors account for about 80% of attacks aimed at the South Korean government sector. In this case, Seoul has not publicly connected the academy breach to Pyongyang or any other actor.
The ministry said it views the increasing sophistication and scope of cyberattacks as a serious concern and will strengthen internal security systems with relevant authorities. That is the standard government line after a breach, but the useful test will be whether officials publish enough detail for other agencies to check for the same weakness.
The incident lands as South Korea faces wider pressure over data security. In June, the country’s data protection regulator issued a $409 million fine against Coupang after a 2025 incident exposed about 33.7 million customer accounts, roughly 65% of South Korea’s population.
South Korea has also rewritten its Personal Information Protection Act, with changes set to take effect in September. The amended law allows fines of up to 10% of turnover for data breaches and explicitly makes the chief executive ultimately responsible for compliance with data protection rules.
This story draws on original reporting from The Record.