South Korea’s Foreign Ministry disclosed a major data breach affecting nearly all the country’s diplomats this week. Hackers reportedly infiltrated an online training system and remained inside for roughly ten months. Consequently, this incident has raised serious concerns about the security of sensitive government personnel records.
Indeed, the breach targeted an education platform operated by the Korea National Diplomatic Academy specifically. This ministry-affiliated institution handles diplomat training and conducts broader foreign affairs research nationwide. According to officials, the compromised system stored approximately 10,000 personnel records overall. These records included serving and former diplomats, overseas mission staff and administrative embassy personnel. However, the ministry has not yet confirmed how many records attackers actually extracted.
Furthermore, exposed data reportedly included names, user IDs, email addresses and encrypted passwords collectively. Officials first became aware of this data breach after another agency alerted them in February. The attacker had reportedly gained server control sometime around April or May 2025. Afterward, the ministry shut down the system and launched a joint investigation immediately.
Notably, the platform launched in 2022 as pandemic-era demand increased for online training programs. Investigators later discovered the attacker exploited a previously unknown zero-day software vulnerability specifically. Since neither the manufacturer nor security authorities knew about this flaw, detection proved genuinely difficult. Nevertheless, officials confirmed the training system remained separate from other critical government networks entirely.
Meanwhile, authorities have not identified the attacker’s origin or determined national responsibility yet. When asked about potential North Korean involvement, officials said insufficient technical evidence currently exists. Therefore, investigators are not ruling out any possibility, including foreign state-backed hacking organizations.
Ultimately, this data breach highlights growing cybersecurity vulnerabilities within government training and administrative systems worldwide. Going forward, the ministry plans to notify affected individuals through stored email addresses eventually. However, reaching former employees with expired accounts may prove particularly challenging moving forward.

