Hack on diplomatic academy triggers chain-reaction fears for public sector

Jul 27, 2026, 09:07 am

print page small font big font

facebook share

tweet share

Seoul's Seocho District, the Korea National Diplomatic Academy. /Yonhap

Fears are growing over potential additional damage to yet-unidentified public institutions following a breach exposing over 10,000 personal data records of diplomats and other officials at the Ministry of Foreign Affairs' Korea National Diplomatic Academy.


According to diplomatic sources on the 26th, the hack resulted from an attack exploiting an undisclosed vulnerability, or a so-called zero-day, in a server security solution developed by a domestic private firm.


The firm is known to have developed server security solutions designed for system access control and internal data loss prevention.


Zero-day vulnerabilities carry the characteristic of being difficult even for developers to detect in advance.


Consequently, possibilities are being raised that other public institutions using the same security solution as the Korea National Diplomatic Academy may have suffered similar attacks.


According to the Ministry of Foreign Affairs, the attackers infiltrated the academy's server around April or May last year and maintained access for about 10 months until February this year.


Given that the Korea Internet & Security Agency recommended security updates for the vulnerability only early last month, observations suggest that the actual victim institutions and scale of damage could be larger.


Attention is also focusing on the possibility of North Korea being named behind the attack.


While some in the security industry analyze a high possibility of North Korean involvement, the ministry is maintaining a principled stance, stating that it is analyzing the situation without ruling out the North Korea possibility.


The security industry is noting that zero-day attacks are a frequent tactic of North Korean hacking groups, and that the attackers intensively targeted the structure and vulnerabilities of domestic security solutions.


They point out that Chinese or Russian hacking groups relatively more often exploit publicly disclosed vulnerabilities, marking a difference from this attack method.


One security expert said that cases of Chinese hackers analyzing South Korean security vendor solutions over long periods to find vulnerabilities and attack are uncommon, adding that they usually exploit externally disclosed vulnerabilities.


A bigger problem is that the leaked information could be abused for secondary attacks targeting public officials in the security sector.


The hack exposed names, emails, and encrypted passwords of security officials, including diplomats.


If attackers combine these with personal data circulating on the dark web, public social media information, or files secured through previous hacks, spear-phishing attacks precisely targeting specific officials become possible.


Another security expert expressed concern that hackers have effectively secured primary information needed for targeted attacks, warning that they could combine it with other data to attempt persistent spear-phishing or launch side-channel attacks through relatively vulnerable routes like e-commerce sites.


A Foreign Ministry official remarking on the case as an unprecedented matter not unrelated to national security is also interpreted as having such potential secondary damage in mind.


Currently, legislation for cybersecurity response remains pending in the National Assembly.


People Power Party Representatives Yu Yong-weon and Kim Sang-hoon each sponsored the National Cybersecurity Act and the Cybersecurity Framework Act last year, but the bills have failed to pass the standing committee, the National Assembly Intelligence Committee.


                                                                                                          Mok Yong-jae

#Hacking #Cyberattack 
Copyright by Asiatoday