Lead

South Korean authorities are investigating a data breach at the Korea National Diplomatic Academy's (KNDA) online education system that may have exposed the personal information of approximately 10,000 individuals, including current and former diplomats, overseas mission staff, and officials from other government agencies. The Foreign Ministry said it was notified of suspicious access in early February and immediately shut down the system, which has remained offline since.

The breach is believed to have begun around April or May 2025, with the attacker maintaining access until February 2026—nearly 10 months without detection. The ministry has stated that the compromised server stored educational videos and trainee information, including names, user IDs, positions, official email addresses, and encrypted passwords. No resident registration numbers, home addresses, or telephone numbers were stored on the server.

Coverage Comparison

Yonhap News reported the breach in a series of articles between July 20 and July 23. Initial reports focused on the ministry's notification and response, while later analysis highlighted concerns about national security and institutional failures. One report noted that the server, located within the ministry headquarters, had been excluded from regular security inspections, and that personal information of retired diplomats and former overseas officials had not been deleted—practices that reflect poorly on information management.

The ministry has acknowledged that the attack exploited a zero-day vulnerability, a previously undisclosed software flaw that made detection difficult. However, analysts have pointed out that the prolonged undetected access raises questions about the ministry's ability to quickly identify and contain intrusions.

Key Claims

  • The breach at the Korea National Diplomatic Academy's online education system exposed approximately 10,000 personnel records, according to ministry officials.
  • The compromised data included names, user IDs, official email addresses, positions, and organizational affiliations, as reported by Yonhap.
  • The attackers gained access between April and May 2025 and maintained access until February 2026, when the ministry was alerted by a related government agency.
  • The server did not contain resident registration numbers, home addresses, or telephone numbers, according to the ministry.
  • The Foreign Ministry shut down the online education system in February 2026 and has kept it offline during the investigation.
  • Intelligence authorities are investigating the possibility of state-backed hacking, including groups linked to North Korea, though no attribution has been confirmed.
  • The ministry plans to change all diplomats' email addresses to prevent potential misuse of the compromised data, such as phishing or other cybercrimes.

Perspectives

The Foreign Ministry has stated that the attack exploited a zero-day vulnerability, making detection difficult, and has emphasized that the full extent of the data leak is not yet known. Officials have not ruled out any possibility regarding the attacker's identity, including involvement by overseas hacker groups.

Analysts and commentators have framed the incident as a broader failure of cybersecurity and information management. They have noted that the breach went undetected for nearly 10 months, raising concerns about the government's ability to respond to sophisticated cyber threats. The exposure of personnel information, particularly of intelligence officers, could pose a serious threat to national security, according to some assessments.