South Korea’s Foreign Ministry said on Tuesday that a cyberattack on a government-run diplomatic academy appears to have exposed a significant volume of data, as authorities investigate whether foreign state-sponsored hackers were involved.
Speaking at a media briefing, ministry spokesperson Park Il said preliminary findings indicate the breach resulted in a “considerable” data leak. However, officials are still assessing the full scope of the incident and have yet to determine exactly what information was compromised.
He said no misuse of leaked data had been confirmed and there was insufficient technical evidence to determine who was behind the attack, although the government was not ruling out any possibilities, including foreign-based hacking groups.
Attack Exploited Zero-Day Vulnerability
The comments followed a ministry statement issued on Monday disclosing that unidentified attackers exploited a previously unknown “zero-day” software vulnerability and security configuration weaknesses to compromise the Korea National Diplomatic Academy’s online education system.
The ministry said the attackers gained control of a server between April and May 2025 and maintained access until February 2026, when suspicious activity was reported by a government agency and the system was blocked.
The statement said the system stored training videos and information needed for course administration, including participants’ names and user IDs, but added that it remained difficult to determine what data had been leaked.
South Korean daily Dong-A Ilbo, citing government sources, reported that personal information belonging to about 6,000 current and former diplomats and officials seconded from other ministries may have been compromised.
Possible North Korean Link
The report said intelligence authorities were investigating whether a North Korean-linked hacking group could have targeted the data, which includes information on diplomats stationed overseas.
Park said the ministry was working closely with relevant agencies to establish the full extent of the breach and strengthen internal cybersecurity systems.
(With inputs from Reuters)





