South Korea says hackers broke into the National Diplomatic Academy’s online education system and stole personal data tied to current and former foreign ministry staff, including diplomats posted abroad. The intrusion reportedly began in April 2025 when an unknown attacker exploited a server vulnerability and remained undetected until February 2026. Exposed data includes IDs, names, email addresses, and encrypted passwords for at least 6,000 people, with some reports putting the total closer to 10,000.
Why it matters: This affects government personnel, including overseas diplomats, whose exposed details could now be used in targeted phishing or espionage. Affected users should treat unexpected messages cautiously and reset or review any reused credentials, while defenders should investigate the vulnerable system and related monitoring gaps.
Bill Toulas
2026.07.22
100% relevant
This article appears to be the first clear disclosure of the South Korean foreign ministry training-system breach affecting diplomats worldwide, so it establishes a distinct new breach story.
← Back to all stories