![]() |
| A cyberattack suspected of leaking the personal information of South Korea's entire diplomatic corps has taken place. Occurring through the Korea National Diplomatic Academy's online education system, the breach is estimated to have exposed up to 10,000 records, including information on former Foreign Ministry officials as well as personnel dispatched to overseas missions from other government ministries. Pictured is the Korea National Diplomatic Academy in Seocho-gu, Seoul, on July 21. / Courtesy of Yonhap News |
The Ministry of Foreign Affairs revealed on July 21 that approximately 10,000 data records pertaining to foreign ministry personnel stored in the Korea National Diplomatic Academy's online education system were leaked following a cyberattack. Concerns are mounting that compromised information—which includes email addresses of diplomats and security-related officials—could expose personnel to further cyber threats such as spear-phishing attacks.
According to the Foreign Ministry, the academy's online education system server was compromised by attackers between April and May of last year, with unauthorized access persisting through February of this year.
The leaked data comprises nearly 10,000 records, containing names, user IDs, email addresses, and passwords of overseas foreign service officers, diplomatic staff, attachés, and administrative personnel at foreign missions. Foreign Ministry officials believe the breach likely includes information on the vast majority of its headquarters staff.
However, sensitive personal data such as personal photos, resident registration numbers, phone numbers, and home addresses were reportedly not compromised.
A Foreign Ministry official told reporters, "After being alerted by relevant agencies in early February to anomalous access patterns, we immediately shut down the system and initiated a joint investigation," adding that "the figure of roughly 10,000 represents the maximum potential scope of damage, which may include duplicate accounts held by single individuals."
Regarding the threat actor, the official noted that further investigation is required, though the ministry has not ruled out state-sponsored hacking groups, including those backed by North Korea.
When asked whether the identity of intelligence officers had been exposed, the official refrained from providing details, stating, "It is our policy not to comment on matters tied to national security."
Addressing concerns over heightened risks of phishing attacks resulting from the unprecedented large-scale leak of diplomats' names and email addresses, the official admitted, "There is no precedent for the entire roster of diplomatic personnel being leaked at once," hinting at elevated national security risks.
The ministry stated that it regularly advises staff to exercise heightened vigilance against email phishing attempts.
Explaining why the breach was disclosed roughly five months after its discovery, the Foreign Ministry noted, "Given the unprecedented nature of the incident, we exercised extreme caution during the investigation, review, and analysis phase, but ultimately decided to make the public announcement in line with opinions favoring transparency."
Meanwhile, the attack was reportedly executed using a zero-day vulnerability—a flaw unknown even to the software vendor.
Because the attacker exploited legitimate software privileges, detecting the intrusion through standard security mechanisms proved exceptionally difficult, the ministry explained.
Mok Yong-jae
1
2
3
4
5
6
7