South Korea’s Ministry of Foreign Affairs disclosed that hackers compromised the Korea National Diplomatic Academy’s e-learning platform and remained inside the system for about nine months, from April 2025 until abnormal access was detected in February 2026. The ministry said the attackers stole personal information belonging to former and current employees, including trainee IDs, names, email addresses, and encrypted passwords, before the affected system was shut down and taken offline.
South Korean officials described the incident as unprecedented, with reporting indicating the breach may have exposed the personal data of nearly all South Korean diplomatic personnel as well as up to 10,000 administrative and intelligence records. The intrusion was reportedly enabled by a previously unknown zero-day vulnerability in server software combined with misconfigured security settings, but authorities have not publicly attributed the attack to any specific threat actor.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
South Korea's Ministry of Foreign Affairs publicly disclosed the Korea National Diplomatic Academy platform breach on July 22, 2026, about five months after discovery. The ministry said exposed data included login IDs, names, email addresses, and encrypted passwords, while national ID numbers and other sensitive personal details were not affected.
South Korea's Ministry of Foreign Affairs disclosed that hackers stole personal information from the Korea National Diplomatic Academy platform, including trainee IDs, names, email addresses, and encrypted passwords. Subsequent reporting said the incident may have exposed nearly all South Korean diplomatic personnel's personal data and up to 10,000 administrative and intelligence records.
In February 2026, the Ministry of Foreign Affairs detected abnormal access to the academy's system and shut it down. The platform had not yet been restored at the time of reporting.
Unidentified attackers compromised the Korea National Diplomatic Academy's e-learning platform, beginning an intrusion that the Foreign Ministry said lasted for months. Reporting said the attackers exploited a previously unknown zero-day in server software along with misconfigured security settings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcecyberveille.ch
Open sourceteiss.co.uk
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourcetherecord.media
Open sourcemofa.go.kr
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.