South Korea Diplomatic Academy Breach
Coverage from BleepingComputer, The Record, and others
Articles
20
Active Days
93
The Topic

Hackers accessed South Korea’s National Diplomatic Academy online system for roughly nine to ten months, potentially exposing records belonging to current and former Foreign Ministry employees, including diplomats. The Ministry took the platform offline after detection by the National Intelligence Service and reported exposure of identifiers, names, email addresses, and encrypted passwords, while the total affected population and exact data accessed remain uncertain. The incident highlights monitoring and configuration weaknesses in a government-hosted system and sits alongside broader South Korean enforcement against inadequate personal-data protection.
First Article: 04/23/26
Latest Article: 07/24/26
Summary
- The National Diplomatic Academy system was compromised from approximately April 2025 to February 2026.
- Reportedly exposed data includes user IDs, names, email addresses, encrypted passwords, and possibly job or departmental information.
- Estimates of affected individuals range from about 6,000 to 10,000 current and former Foreign Ministry personnel.
- The National Intelligence Service detected the intrusion; the Ministry then blocked access and added security measures.
- Reports describe a server vulnerability, potentially including a zero-day flaw, combined with misconfigured security settings.
- The attacker and the precise data accessed or exfiltrated have not been confirmed.
- South Korea’s privacy regulator separately fined matchmaking service Duo over the exposure and retention of sensitive member data.
History
The update sharpens the National Diplomatic Academy breach into a longer, better dated incident with a clearer response timeline and a narrower but more concrete view of what data may have been exposed. It also drops the earlier broader enforcement context in favor of a separate, less-detailed mention of the Duo fine.
The story now adds stronger detail on the academy compromise, including a wider estimated victim count and a specific server vulnerability, while confirming that regulators have broadened enforcement into retention and database-security failures. It also introduces a new policy angle: South Korea is preparing tougher privacy penalties and executive accountability.
