- South Korea’s government reveals ten-month cyber attack on National Diplomatic Academy’s online education system
- Data stolen included user IDs, names, emails and encrypted passwords of at least 6,000 people
- The State Department shut down IT systems, implemented enhanced security and delayed disclosure due to diplomatic sensitivities
Current and former employees of the South Korean Ministry of Foreign Affairs (MFA) as well as other government personnel may have had their data siphoned off by cybercriminals in an attack that lasted ten months.
The South Korean government has revealed an attack against the online education system of its National Diplomatic Academy. The system, created in 2022 by the nation’s premier institution for the education and training of diplomats, apparently contained a security vulnerability that unnamed threat actors managed to exploit.
In a statement published on the South Korean government’s official website, both the details of the bug, as well as the attackers, were not disclosed.
Thousands are affected
However, it noted that the attack took place between April 2025 and February 2026. During these ten months, cybercriminals were able to steal user IDs, names, emails, as well as encrypted passwords from trainees in the National Diplomatic Academy Online Education System.
Unique identification information, sensitive information, mobile phone numbers, home addresses and photos were not compromised, it said.
In response to the attack, the MFA shut down its entire IT infrastructure and implemented “enhanced security measures”, without elaborating on what those measures were. It urged all staff to remain vigilant about incoming emails and to take action if they receive anything “suspicious”.
While the official announcement lacks details, Bleeping Computer reported that the attack affected “at least 6,000 people, 350 of whom were current government attachés sent abroad.” Citing an MFA spokesman, the publication said the ministry decided to reveal the incident with a five-month delay due to the “sensitive nature” of the attack and the need to analyze it thoroughly before making it public.
“We acknowledged this issue in February, but we announced it five months later due to the sensitivity of the matter regarding our diplomatic and security affairs and the need for careful review and analysis,” South Korea’s Foreign Ministry spokesman Park Il said.
Via Bleeping Computer
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



