Hackers were inside South Korea's diplomat training system for 9 months
Hackers gained unauthorized access to South Korea's diplomat training system for nine months, stealing personal information from former and current Ministry of Foreign Affairs employees. The breach was facilitated by a previously unknown zero-day vulnerability and misconfigured security settings, highlighting a growing concern about cyberattacks targeting South Korean government institutions.
Hackers gained unauthorized access to South Korea’s diplomat training system for nine months, stealing personal information from former and current Ministry of Foreign Affairs employees. The breach of the Korea National Diplomatic Academy’s e-learning platform occurred from April 2025 to February 2026, when a related government authority notified the ministry of abnormal access to the system. The ministry said it immediately shut the system down and has not restored it since. Compromised data is believed to include “the ID, name, email, and encrypted password of the trainee,” according to the ministry, adding that “sensitive information” including contact details and personal photos were not affected. According to the JoongAng Daily newspaper, the unidentified attacker exploited a previously unknown zero-day vulnerability in the server software, compounded by misconfigured security settings, to access the network. “No security update was available at the time, which limited our ability to respond,” the ministry said. The Korea National Diplomatic Academy trains diplomatic service candidates, serving diplomats preparing for overseas postings, and senior officials from across central and local government. The breadth of its user base has prompted concern among lawmakers and security analysts about the potential scope of the exposure. The ministry said it could not yet determine precisely what information had been accessed or exfiltrated during the period of compromise. “We view the growing sophistication and expanding scope of cyberattacks as a matter of serious concern,” the ministry said, adding that it would continue strengthening internal security systems in cooperation with relevant authorities. The incident is the latest in a series of high-profile data incidents that have intensified pressure on Seoul to overhaul its approach to digital security. In June, South Korea’s data protection regulator issued a record fine of $409 million against e-commerce giant Coupang, following a 2025 incident that exposed roughly 33.7 million customer accounts — equivalent to around 65% of South Korea's entire population. The incidents have helped drive a landmark rewrite of South Korea’s Personal Information Protection Act, which is set to take effect in September. The amended law allows companies to be fined up to 10% of their turnover for data breaches, and explicitly designates the CEO as the person ultimately responsible for data protection compliance.
