Last Update: 08/01/2026 at 12:00 PM EST

South Korea Diplomatic Academy Breach

Coverage from BleepingComputer, The Record, and others

Articles

20

Active Days

93

The Topic

South Korea Diplomatic Academy Breach topic image

Hackers accessed South Korea’s National Diplomatic Academy online system for roughly nine to ten months, potentially exposing records belonging to current and former Foreign Ministry employees, including diplomats. The Ministry took the platform offline after detection by the National Intelligence Service and reported exposure of identifiers, names, email addresses, and encrypted passwords, while the total affected population and exact data accessed remain uncertain. The incident highlights monitoring and configuration weaknesses in a government-hosted system and sits alongside broader South Korean enforcement against inadequate personal-data protection.

First Article: 04/23/26

Latest Article: 07/24/26

Summary

  • The National Diplomatic Academy system was compromised from approximately April 2025 to February 2026.
  • Reportedly exposed data includes user IDs, names, email addresses, encrypted passwords, and possibly job or departmental information.
  • Estimates of affected individuals range from about 6,000 to 10,000 current and former Foreign Ministry personnel.
  • The National Intelligence Service detected the intrusion; the Ministry then blocked access and added security measures.
  • Reports describe a server vulnerability, potentially including a zero-day flaw, combined with misconfigured security settings.
  • The attacker and the precise data accessed or exfiltrated have not been confirmed.
  • South Korea’s privacy regulator separately fined matchmaking service Duo over the exposure and retention of sensitive member data.

History

07/27/2026

The update sharpens the National Diplomatic Academy breach into a longer, better dated incident with a clearer response timeline and a narrower but more concrete view of what data may have been exposed. It also drops the earlier broader enforcement context in favor of a separate, less-detailed mention of the Duo fine.

07/25/2026

The story now adds stronger detail on the academy compromise, including a wider estimated victim count and a specific server vulnerability, while confirming that regulators have broadened enforcement into retention and database-security failures. It also introduces a new policy angle: South Korea is preparing tougher privacy penalties and executive accountability.

Full History

Featured

Timeline: 93 Days

Apr 23May 14May 28Jun 18Jul 2Jul 23

Additional Articles

⭐⭐⭐⭐⭐

Yahoo04-23-2026
South Korea's Personal Information Protection Commission fined Duo in connection with a January hack exposing sensitive member data from the Duo matchmaking service.
SC Media07-23-2026
South Korea's National Intelligence Service discovered a 10-month breach of the National Diplomatic Academy system in February 2026, exposing personal data of Ministry of Foreign Affairs employees.
Circuit Magazine07-24-2026
South Korea's Foreign Ministry disclosed in 2026 that hackers accessed the Korea National Diplomatic Academy training platform for ten months, stealing credential data.
Business & Human Rights05-14-2026
Boram Sangjo was fined in South Korea after a May 2024 hacking incident exposed 27,882 personal information records, with late breach notification and improper retention.
U.S. News / Kyu-seok Shim04-23-2026
South Korea's Personal Information Protection Commission fined Duo in 2024 after a January hack exposed sensitive matchmaking members' personal data.
Business Human Rights05-18-2026
Boram Sangjo Development received an administrative fine in South Korea after a May 2024 hacking incident exposed 27,882 personal data items and triggered delayed breach notice.
Seoul Economic Daily / Hwang Dong-Geon04-26-2026
South Korea police and the PIPC investigated a Duo Info breach after exposure of detailed matchmaking and personal data for 430,000 members, with notification delayed until the PIPC announcement.
UPI07-21-2026
South Korea's Foreign Ministry announced a data breach at the Korea National Diplomatic Academy online system after suspicious access notifications in early February.
The Korea Herald06-22-2026
South Korea's Ministry of SMEs and Startups announced trade secret certification and security inspections after a breach exposed data from 5,000 Startup for All applicants in Seoul.
Korea JoongAng Daily06-22-2026
South Korea SMEs minister Han Seong-sook apologized after a Startup For All Project breach exposed first-round applicants' ideas and email addresses, with investigation underway.
Bloomberg / Mark Anderson07-21-2026
South Korea investigates a suspected data leak at a government-run diplomat training academy, with about 10,000 diplomat records potentially affected.
Business & Human Rights05-18-2026
Boram Sangjo faced an administrative fine in South Korea after May 2024 hacking exposed 27,882 records and triggered delayed breach notification and retention violations.

⭐⭐⭐

Business Human Rights05-18-2026
Boram Sangjo received an approximately 554 million won administrative fine after a May 2024 hacking incident exposed member personal data in South Korea.
UPI05-01-2026
South Korea Financial Supervisory Service reportedly ordered a 4.5 month suspension of Lotte Card after a breach exposed nearly three million customers.
Business and Human Rights05-18-2026
Boram Sangjo was fined for a May 2024 personal data breach in which 27,882 records were exposed, with enforcement tied to late notification and retention failures.
Business Human Rights05-14-2026
Boram Sangjo in South Korea was fined in 2024 after a May 2024 hack exposed 27,882 personal records and breach notices were sent after the statutory deadline.