기사 메일전송
Ministry of Foreign Affairs Headquarters Server Breached… “Information of Over 6,000 Individuals, Including Diplomats, Leaked; North Korea Suspected as the Likely Perpetrator”
  • Lim Yo-hee
  • July 21, 2026 at 1:22 PM
기사수정
  • 10 months of exposure on the Korea National Diplomatic Academy online education system

  • Information of approximately 6,000 diplomats and resident staff leaked
  • Intelligence authorities: “Investigating possibility of North Korea-related group”

The commemorative stone at the Korea National Diplomatic Academy. [Photo: Yonhap News]

It has been confirmed that the personal information of approximately 6,000 South Korean diplomats and government officials dispatched overseas has been leaked in a hacking attack suspected to have been carried out by a North Korea-linked organization.

 

Despite the breach occurring on a server located within the Ministry of Foreign Affairs headquarters, the government failed to detect the intrusion for nearly 10 months, leading to criticism that a serious hole has been blown in the nation's diplomatic and security network.

 

10-Month Hacking Streak... "Suspected North Korean Involvement"

 

According to the Ministry of Foreign Affairs and intelligence authorities on the 20th, unidentified hackers infiltrated the security software server of the Korea National Diplomatic Academy's online education system, remaining embedded for approximately 10 months from April–May last year until February of this year to siphon off personal information.

 

Intelligence authorities are focusing their investigation on the possibility that this incident was the work of a North Korea-linked hacking group targeting the identities of South Korean diplomats and government officials stationed at overseas missions worldwide.

 

As the Korea National Diplomatic Academy is a key national think tank responsible for training diplomats and researching foreign policy and security, it is highly likely that this attack was not merely for data theft, but a preliminary operation to identify key diplomatic personnel for follow-up activities.

 

The scale of the breach is concerning, as the approximately 6,000 affected individuals include about 2,500 active-duty diplomats currently serving around the world.

 

Furthermore, it has been reported that the leak includes approximately 350 officials dispatched from other government ministries, retired diplomats, officials who have returned to their original departments, and potentially even intelligence agents.

 

Exploiting 'Zero-Day' Vulnerabilities... Foreign Ministry Remained Unaware of Breach

 

The hackers persistently exploited a "zero-day" vulnerability—an unknown security flaw in server software—and gaps in the system's security configurations.

 

A Ministry of Foreign Affairs official explained, "Because they used a zero-day vulnerability that even the software manufacturer was unaware of to access the system with legitimate credentials, it was difficult to detect using standard methods, and there were no security updates available."

 

The core issue lies in the Ministry's lax management system. Although the compromised server was located inside the Ministry of Foreign Affairs headquarters at the Government Complex Seoul Annex, it had been omitted from the Ministry’s regular security inspections. The Ministry only managed to shut down the system in early February of this year after being notified of abnormal access by the National Intelligence Service.

 

The Ministry also faces criticism for exacerbating the scale of the damage by failing to delete and instead neglecting the personal information of retirees and officials who had returned to their original departments.

 

The Ministry of Foreign Affairs stated, "The system stored educational videos and administrative information such as the names and IDs of participants, and at this moment, it is difficult to specify the exact extent of the leaked data." They added that they have been conducting a thorough investigation in cooperation with relevant agencies since the system shutdown in February.

 

However, with concerns raised that the identities of some intelligence personnel may have been included, a red alert has been issued for the safety of personnel operating overseas and the security of the nation's intelligence network. The government plans to overhaul its security systems and strengthen monitoring of North Korea-related information security as soon as the investigation results are finalized.


Reporter Im Yo-hee


What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site