South Korea has revealed that hackers secretly accessed the National Diplomatic Academy’s online education system for nearly 10 months, exposing personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including diplomats stationed overseas.

According to the ministry, the breach began in April 2025 after an unknown threat actor exploited a vulnerability in the Academy’s server. The attackers remained undetected until February 2026, during which time they accessed data linked to at least 6,000 people, including around 350 diplomats serving abroad.

The compromised platform was launched in 2022 to provide remote training during the COVID-19 pandemic and later became a permanent system for government employee training and video conferencing.

Officials say the leaked information includes user IDs, names, email addresses, and encrypted passwords of registered users. The ministry stated that national identification numbers, phone numbers, photographs, home addresses, and other sensitive personal information were not exposed.

Following the discovery, the Ministry of Foreign Affairs disabled access to the online education system and introduced additional security measures to strengthen its defenses. During a press briefing, ministry spokesperson Park Il said the government delayed publicly announcing the incident because of its diplomatic and national security implications, explaining that authorities needed time for a thorough investigation before disclosing the breach.

The ministry is urging anyone who may have been affected to remain alert for phishing emails and other suspicious communications, especially messages received from unknown or unverified senders, and to report any concerns to its security department.

READ
Public WordPress 'wp2shell' Exploits Released, Millions of Sites Urged to Patch Immediately

Local media reports suggest the total number of affected individuals could be as high as 10,000, while some reports also claim that official job titles and departmental affiliations were exposed. Investigators believe one reason the intrusion went unnoticed for so long was that the compromised server was located inside the Ministry’s headquarters and was excluded from routine security monitoring.


Buy ExpressVPN with PayPal or Credit Card

According to Korean media, the breach was ultimately discovered in February 2026 by South Korea’s National Intelligence Service, which then alerted the Ministry of Foreign Affairs about the compromise.

Advertisement