South Korea’s Ministry of Foreign Affairs revealed on July 21 that its National Diplomatic Academy’s online training system was hacked, with about 10,000 personal data records likely compromised [1, 2, 3, 4]. The breach affected both active and retired diplomatic staff who used the system.

The unauthorized access began between April and May 2025 and continued intermittently until early February 2026, when the Ministry was notified and the system was shut down [1, 5, 2, 6, 3, 4]. The government agency detecting suspicious activity alerted the Ministry, which immediately took the system offline for investigation [1, 5, 2, 6, 3, 4].

Leaked data reportedly included names, user IDs, job titles, email addresses, and encrypted passwords [1, 5, 2, 6, 3, 4]. Sensitive personal information such as ID numbers, phone numbers, and home addresses were not stored on the hacked system and were not leaked [1, 5, 2, 6, 3, 4].

Park Il, Foreign Ministry spokesperson, said, "It appears that a significant amount of data has been leaked. Govt is not ruling out any possibilities, including hacking organisations behind the scenes involving other countries" [6]. Authorities consider the hack a national security issue and have not excluded foreign or overseas hacker groups. North Korean and Chinese hacker organizations are among those under investigation [1, 5, 2, 6, 3, 4].

Investigators believe the attack exploited an unknown zero-day vulnerability in the software, enabling the hacker to operate with normal system privileges and evade early detection [3]. The system remains offline as authorities continue to investigate.

The Ministry has not disclosed whether any data has been misused yet but is treating the breach with high priority given the sensitive nature of the personnel affected. The incident continues to be under active investigation with no clear timeline provided for restoring the system [1, 5, 2, 6, 3, 4].