- South Korean government reveals 10-month cyberattack on National Diplomatic Academy’s online education system
- The stolen data included the user IDs, names, emails and encrypted passwords of at least 6,000 people.
- MFA shut down IT systems, deployed enhanced security and delayed disclosure due to diplomatic sensitivity
Current and former employees of South Korea’s Ministry of Foreign Affairs (MFA), as well as other members of the government, may have had their data siphoned off by cybercriminals in a ten-month attack.
The South Korean government has revealed an attack on the online education system of its National Diplomatic Academy. The system, implemented in 2022 by the country’s premier institution for the education and training of diplomats, apparently contained a security flaw that anonymous malicious actors managed to exploit.
In an announcement posted on the official South Korean government website, neither details of the breach nor those of the attackers were disclosed.
Thousands of people are affected
However, it was noted that the attack took place between April 2025 and February 2026. During these ten months, cybercriminals were able to steal user IDs, names, email addresses as well as encrypted passwords of trainees from the National Diplomatic Academy’s online education system.
Unique identifying information, sensitive information, cell phone numbers, home addresses and photos were not compromised, it added.
In response to the attack, MFA shut down its entire IT infrastructure and deployed “enhanced security measures,” without specifying what those measures were. He urged all employees to remain vigilant of incoming emails and to contact us if they receive anything “suspicious.”
Even though the official announcement lacks details, BeepComputer reported that the attack affected “at least 6,000 people, 350 of whom are current government attachés sent abroad.” Citing a Foreign Ministry spokesperson, the publication said the ministry decided to disclose the incident five months late due to the “sensitive nature” of the attack and the need to analyze it in depth before making it public.
“We recognized this issue in February, but announced it five months later due to the sensitivity of the issue regarding our diplomatic and security affairs, and the need for careful review and analysis,” said Park Il, a spokesperson for the South Korean Foreign Ministry.
Via BeepComputer
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




