Contained Medium impact Data breach Checked 2d ago

South Korean diplomatic academy breach exposes staff data

Hackers spent about 10 months inside the Korea National Diplomatic Academy's online training system. Personal data belonging to current and former Foreign Ministry staff, including overseas diplomats and intelligence agency personnel, may have leaked. The system remained blocked while government agencies investigated, and the ministry planned to change all diplomats' email addresses. Police opened a formal criminal investigation, and in August the Foreign Ministry drew criticism in parliament for leaving out the breach in a briefing to the president and for admitting the system's firewall had been left open. As of August 21, security authorities said they suspect North Korea was behind the intrusion. In early September, the ministry said it would sharply increase its cybersecurity budget for next year in response.

Started
Jul 20, 2026
Latest activity
Sep 1, 2026
Attributed to
North Korea-linked hackersSuspected
Where
South Korea
Sectors
Government
Scale
one government training system holding more than 10,000 records, including diplomats and intelligence agency personnel

Current status

No credible incident-specific reporting or official statement dated after September 1, 2026 was found through September 9; the latest known update remains the Foreign Ministry's cybersecurity budget increase.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

No named government agency has moved beyond suspicion; South Korean authorities said as of August 21 they suspect North Korea, and no source since has confirmed or changed that.

Impact

The exposed data may include names, user IDs, email addresses, and encrypted passwords. The ministry said national identification data, sensitive information, phone numbers, home addresses, and photographs were not included. A later report said intelligence agency personnel were also among those whose information may have been exposed.

What to do

Affected staff should treat unexpected email with care and change any password reused elsewhere; other readers do not need to act.

Timeline

  1. Sep 1, 2026

    South Korean outlets reported the Foreign Ministry's proposed 2027 budget quadruples its cybersecurity spending from about 3.8 billion won to about 15.5 billion won, citing the diplomatic academy hack and regional security concerns as reasons.

    Containednews.tf.co.kr
  2. Aug 21, 2026

    Dong-A Ilbo reported that South Korean security authorities suspect North Korea was behind the diplomatic academy breach, and said the exposed data included personal information of intelligence agency personnel in addition to diplomats. The report appeared alongside coverage of a separate, unrelated breach of a private certification firm that exposed a senior presidential office official's contact details, which police are also probing for a possible Lazarus Group link.

    Containeddonga.com
  3. Aug 19, 2026

    Foreign Minister Cho Hyun told the National Assembly's Foreign Affairs and Unification Committee that the system's firewall had been left open during the breach and that he only learned of it later, and apologized for the delayed report.

    Containedmsn.com
  4. Aug 5, 2026

    Reports said Foreign Minister Cho Hyun gave a briefing to the president on August 5 but left out any update on the diplomatic academy hack, drawing criticism that the ministry avoided reporting on the incident.

    Containedmsn.com
  5. Jul 30, 2026

    Reports said the police investigation was expected to face difficulty because a foreign hacking group may be involved, making it hard to pin down responsibility and the scope of the leak.

    Containedmsn.com
  6. Jul 29, 2026

    South Korea's National Police Agency National Investigation Headquarters confirmed it had opened a formal probe into the breach, which exposed up to 10,000 diplomats' personal records, and said it was looking into possible North Korean or Chinese involvement.

    Containedchosun.com
  7. Jul 23, 2026

    The Foreign Ministry planned to change all diplomats' email addresses to reduce the risk of misuse. The training system remained shut down and the investigation continued.

    Containedkoreatimes.co.kr
  8. Jul 22, 2026

    South Korea's national security adviser said investigators were considering several possibilities and had not identified who was responsible.

    upi.com
  9. Jul 21, 2026

    The ministry said the leak appeared substantial but reported no confirmed misuse and no firm evidence identifying the attacker.

    yahoo.com
  10. Jul 20, 2026

    The Foreign Ministry disclosed that attackers had accessed the training system from April 2025 through February 2026 and said it had blocked the system.

    Containedmofa.go.kr

Sources

Related reports