South Korea's diplomat training site leaks personal data

Published July 4, 2026

An attacker group stole personal details from current and former South Korean diplomats by breaking into the National Diplomatic Academy's online training system. The breach lasted ten months before being discovered.

Report priority
Medium
Victim
National Diplomatic Academy

What to do

Check if you're a current or former diplomat or employee of South Korea's Ministry of Foreign Affairs who used the National Diplomatic Academy's online training system between 2022 and 2023.

Contact the South Korean Ministry of Foreign Affairs for guidance on protecting your personal information, as they may offer assistance or identity monitoring services.

Reported details

An attacker group sends fake emails with malicious links to diplomats' work accounts. When clicked, the links trick the system into sending the attacker the victim's login details and personal data. The attacker then steals the data and sells it on underground forums.

The breach involved a server hosting the National Diplomatic Academy's e-learning platform, exploited via an unspecified vulnerability starting around April 2025. Exposed data covers account IDs, names, email addresses, and encrypted (hashed) passwords, plus job titles and departmental affiliations per Korean media. MFA states no resident registration numbers, phone numbers, photos, or home addresses were taken. The server sat inside MFA headquarters and was excluded from routine security scans, which let the intrusion run undetected for about ten months until South Korea's National Intelligence Service flagged it in February 2026; public disclosure followed five months later.