Hackers Lurked for 10 Months Inside South Korea Diplomatic System
South Korea's National Diplomatic Academy's online training system was hacked for nearly 10 months, leaking personal data of diplomats and ministry staff. The breach started in April 2025 and was only fixed in February 2026.
- Report priority
- Medium
- Victim
- National Diplomatic Academy
What is known
An attacker found and abused a security flaw in the academy's online training platform, gaining access to its systems.
What to do
If you were a current or former employee of South Korea's Ministry of Foreign Affairs or a diplomat who used the academy's online training system between April 2025 and February 2026, contact the Ministry of Foreign Affairs for guidance on protecting your personal data, as they have not yet released specific recovery steps for affected individuals.
Reported details
The attacker sent a specially crafted request to the academy's online training system. The system's security failed to block it, letting the attacker move around inside the system. Over months, the attacker copied and stole personal data from thousands of diplomats and ministry employees.
An unidentified threat actor exploited an unspecified security vulnerability in the National Diplomatic Academy's online education platform to gain unauthorized access between April 2025 and February 2026. The breach exposed personal data of current and former employees of South Korea's Ministry of Foreign Affairs, including diplomats stationed overseas, with estimates suggesting 6,000 to 10,000 individuals affected. The platform, deployed in 2022 for remote training and video conferencing, remained compromised for nearly 10 months before the intrusion was detected.
References
- nvd.nist.gov vdb entry
- mofa.go.kr · view.do The Cyber Express
- cyble.com · what-is-a-data-breach The Cyber Express
- donga.com · 2 The Cyber Express
- securityweek.com · data-breach-confirmed-after-australian-energy-giant-origin-is-hacked SecurityWeek
- securityweek.com · upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses SecurityWeek
- infosecurity-magazine.com · lidl-notifies-customers-of Infosecurity Magazine
- sygnia.co · when-technical-controls-work-attackers-change-the-rules Sygnia
- stepsecurity.io · injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys StepSecurity
- thehackernews.com · exposed-server-reveals-ai-assisted.html TheHackerNews
- thehackernews.com · chaos-ransomware-uses-msarat-to-route.html TheHackerNews
- bleepingcomputer.com · new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic BleepingComputer
- securitylabs.datadoghq.com · not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor Datadog Security Labs
- neuracybintel.com · microsofts-july-2026-patch-tuesday-fixes-hundreds-of-vulnerabilities-including-multiple-actively-exploited-zero-days NeuraCybIntel
- msrc.microsoft.com · update-guide NeuraCybIntel
- cisa.gov · known-exploited-vulnerabilities-catalog NeuraCybIntel
- microsoft.com · blog NeuraCybIntel
- acn.gov.it · operational-summary-1-semestre-2026 ACN CSIRT Italy
- acn.gov.it · operational-summary-giugno-2026 ACN CSIRT Italy
- infosecurity-magazine.com · university-ransomware-attacks-rise Infosecurity Magazine