Korea National Diplomatic Academy training platform breach via zero-day
South Korea's Foreign Ministry disclosed that attackers exploited a zero-day vulnerability to keep access to the Korea National Diplomatic Academy's online training system for about ten months, exposing data on thousands of current and former diplomats.
- Victim
- Korea National Diplomatic Academy (Ministry of Foreign Affairs)
- users
- 6.0K
In late July 2026, South Korea's Ministry of Foreign Affairs disclosed that an unidentified attacker had maintained access to the online training platform of the Korea National Diplomatic Academy (KNDA), the ministry's diplomat-training institution, from April 2025 until February 2026. The intruder exploited a previously unknown (zero-day) software vulnerability together with security configuration weaknesses, and the breach went unnoticed for roughly ten months.
Suspicious activity was spotted in February 2026, at which point the system was taken offline. The ministry attributed the five-month gap before public disclosure to the sensitivity of the matter and the need for coordination between agencies.
What was exposed
The compromised system held user IDs, names, email addresses and encrypted passwords of current and former Foreign Ministry personnel and other government officials, with job titles and department affiliations in some records. Reporting put the number of affected people at about 6,000, including several hundred serving diplomats, from a database that may have held up to 10,000 records. The ministry said resident registration numbers, phone numbers, home addresses and photos were not compromised, and it warned staff to be careful with unsolicited emails.
Why it matters
Officials did not formally attribute the intrusion, saying technical analysis was ongoing, but authorities were examining a possible link to North Korean state-backed groups, whose tradecraft researchers said it resembled. A roster of diplomats with verified work emails and roles is a ready-made target list for spear-phishing, which makes a "low sensitivity" training platform a valuable stepping stone for espionage.
Timeline
An unidentified attacker gains access to the Korea National Diplomatic Academy's online education system by exploiting a zero-day vulnerability and configuration weaknesses.
Suspicious activity is detected and the system is taken offline.
The Ministry of Foreign Affairs publicly discloses the breach, citing the sensitivity of the matter and interagency coordination for the five-month delay.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/07/23/south-korea-diplomatic-academy-data-breach/
- koreajoongangdaily.comhttps://www.koreajoongangdaily.com/korea/korean-diplomatic-academys-training-platform-was-hacked-for-nearly-10-months-and-no-one-knew/12782219