South Korea's National Diplomatic Academy suffered a cyberattack that may have leaked the personal information of approximately 10,000 people [1].
The breach is significant because the affected individuals include nearly all current South Korean diplomats, as well as retired officials, and dispatched personnel. Because these individuals handle sensitive international relations and state secrets, the exposure of their personal data presents a substantial security risk.
According to government reports, the hacking targeted the academy's online education system [2]. The unauthorized access occurred over a period of about 10 months, beginning around April 2025 and continuing through February 2026 [2].
South Korea's Ministry of Foreign Affairs said that hacker groups from North Korea or China may be responsible for the attack [2]. The ministry faced questions regarding the delay in announcing the breach to the public.
A spokesperson for the Ministry of Foreign Affairs said the analysis took time because the incident was unprecedented and involved national security [2].
The National Diplomatic Academy, located in Seoul, serves as the primary training institution for the nation's foreign service officers. The potential leak of 10,000 records [1] suggests a systemic failure in the security of the digital infrastructure used to train the country's top diplomats.
Officials are continuing to analyze the extent of the data theft to determine exactly what information was accessed. The government has not yet confirmed the specific types of personal data compromised, though the scale suggests a broad sweep of the academy's user database.
“The breach is significant because the affected individuals include nearly all current South Korean diplomats.”
This breach highlights a critical vulnerability in the digital training infrastructure of South Korea's diplomatic corps. By targeting an educational system rather than a primary government database, attackers were able to maintain access for nearly a year. The potential compromise of the entire current diplomatic workforce provides foreign intelligence agencies with a comprehensive directory of personnel, which could be used for targeted phishing, blackmail, or espionage operations.


