South Korea has disclosed that hackers compromised an online education platform operated by the Korea National Diplomatic Academy (KNDA), exposing personal information belonging to current and former employees of the Ministry of Foreign Affairs, including diplomats stationed overseas. According to the ministry, the attackers remained inside the system for approximately ten months before the intrusion was detected and the affected platform was taken offline.

 

 

The Ministry of Foreign Affairs said the attackers gained unauthorized access sometime between April and May 2025 and maintained access until February 2026. The breach came to light after another government agency detected suspicious activity and alerted the ministry, prompting officials to disconnect the online training system and launch an investigation. The platform has remained offline while forensic experts examine the incident and determine the full scope of the compromise.

According to the ministry, the attackers exploited a previously unknown zero-day vulnerability together with security configuration weaknesses affecting the academy’s online learning environment. Officials said no security update addressing the vulnerability was available when the attackers initially breached the system, making the intrusion difficult to prevent. Investigators are still examining exactly how the compromise unfolded and whether additional vulnerabilities were abused during the attack.

The compromised server stored training materials and personal information associated with users of the academy’s e-learning platform. Potentially exposed data includes names, user IDs, job positions, email addresses, and encrypted passwords belonging to trainees and ministry personnel. Officials said highly sensitive information, including national identification numbers, home addresses, mobile phone numbers, and personal photographs, does not appear to have been affected based on the investigation so far.

The ministry estimates the platform contained approximately 10,000 records, meaning nearly all current and former South Korean diplomats, as well as some officials from other government agencies who participated in diplomatic training programs, could have been impacted. Authorities stressed that this figure represents the maximum number of potentially affected records and that investigators have not yet confirmed how much of the stored information was actually accessed or exfiltrated.

South Korean officials have not attributed the attack to a specific threat actor. During a press briefing, ministry representatives said there is currently no technical evidence identifying those responsible, although investigators have not ruled out the possibility of involvement by a foreign state-sponsored hacking group. Reuters reported that authorities are examining all possibilities, including a potential North Korean connection, but emphasized that no attribution has been made at this stage.

The Ministry of Foreign Affairs said affected individuals are being notified while the investigation continues. Officials also announced plans to strengthen internal cybersecurity controls and improve system security in cooperation with relevant government agencies to reduce the risk of similar incidents affecting diplomatic infrastructure in the future.

Leave a Reply