South Korea's Diplomatic Data Breach: 10-Month Intrusion Revealed

· cybersécurité, Corée du Sud, diplomatie, fuite de données, zero-day

South Korea's Diplomatic Data Breach: 10-Month Intrusion Revealed

South Korea disclosed a 10-month cyberintrusion (April 2025–February 2026) targeting the personal data of 6,000 diplomats and staff via a zero-day flaw in its online training system. No evidence of malicious exploitation has been confirmed.

South Korea's Diplomatic Data Breach: A Ten-Month Security Lapse

The Breach: What Happened?

South Korea revealed a cyberintrusion affecting the personal data of its diplomats and employees of the Ministry of Foreign Affairs. Hackers exploited a zero-day vulnerability in the online training system of the National Diplomatic Academy. The unauthorized access lasted ten months, from April 2025 to February 2026.

At least 6,000 individuals are affected, including 350 government attachés stationed abroad. The stolen data includes credentials, names, email addresses, and encrypted passwords. No sensitive information such as mobile phone numbers or personal addresses was compromised.

The hacked server, hosted at the ministry’s headquarters, evaded regular security checks. It had been used for remote training since 2022, including video conferences and language courses.

Government Response and Measures

The ministry immediately cut off access to the compromised system. A overhaul of email addresses for all diplomats is planned to mitigate impersonation risks. Potentially affected individuals are urged to report any suspicious messages.

Disclosure of the incident was delayed by five months. Authorities justify the delay due to the sensitivity of diplomatic issues and the need to analyze the consequences. The National Intelligence Service discovered the flaw in February 2026 before alerting the ministry.

Potential Implications and Risks

The exposed data could be used for phishing attacks or other cyberthreats, according to the complaint. The ministry fears unpredictable damage and harm to the credibility of diplomatic exchanges. Professional titles and affiliations of the victims are among the compromised information.

No evidence currently confirms malicious use of the data.

Investigation and Attribution

The hackers exploited a zero-day vulnerability. South Korean authorities have not officially attributed the attack.

The technical investigation continues to determine the exact extent of the damage. The ministry rejects speculation linking the delayed communication to other diplomatic matters. It cites the complexity of the analysis and coordination between government agencies.

Key Points

  • 10-month cyberintrusion (April 2025–February 2026) on a server of the South Korean Ministry of Foreign Affairs
  • 6,000 individuals affected, including 350 diplomats stationed abroad
  • Stolen data: credentials, names, emails, and encrypted passwords (no phone numbers or personal addresses)
  • Zero-day vulnerability exploited
  • Five-month delay in disclosure, justified by diplomatic sensitivity

Sources

  1. BleepingComputer - "South Korea discloses data breach impacting diplomats worldwide". (secondary)
  2. Yonhap News - "Foreign ministry plans to change diplomats' email addresses after data breach". (secondary)
  3. Help Net Security - "Months-long breach exposes South Korean diplomats’ personal data". (secondary)

Transparency: 3 sources (0 primary, 3 secondary). Verification: July 23, 2026.

Truthyx - July 23, 2026