- South Korean government discloses ten‑month cyberattack on the National Diplomatic Academy’s online education system
- Data stolen included user IDs, names, emails, and encrypted passwords of at least 6,000 individuals
- MFA shut down IT systems, deployed enhanced security, and delayed disclosure due to diplomatic sensitivity
Current and former employees of the South Korean Ministry of Foreign Affairs (MFA), as well as other government personnel, may have had their data siphoned out by cybercriminals in an attack that lasted for ten months.
The South Korean government has disclosed an attack against the online education system of its National Diplomatic Academy. The system, set up in 2022 by the country’s premier institution for educating and training diplomats, apparently contained a security vulnerability that unnamed threat actors managed to exploit.
In an announcement published on the official website of the South Korean government, both the details about the flaw, as well as about the attackers, were not disclosed.
Thousands are affected
However, it did note that the attack took place between April 2025 and February 2026. During these ten months, cybercriminals were able to steal user IDs, names, emails, as well as encrypted passwords of trainees in the National Diplomatic Academy Online Education System.
Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not compromised, it said.
In response to the attack, MFA shut down its entire IT infrastructure and deployed “enhanced security measures”, without elaborating what these measures were. It urged all employees to remain vigilant of incoming emails, and to reach out if they receive anything “suspicious”.
While the official announcement lacks details, BleepingComputer reported that the attack impacted “at least 6,000 individuals, 350 of them being current government attachés dispatched abroad.” Citing an MFA spokesperson, the publication said the Ministry decided to disclose the incident with a five-month delay due to the “sensitive nature” of the attack, and the need to thoroughly analyze it before going public.
“We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis,” said South Korea Foreign Ministry’s spokesperson Park Il.
Via BleepingComputer
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

