For the better part of a year, hackers are believed to have gained access to the personal information of as many as 10,000 individuals from the online educational server of the Korea National Diplomatic Academy (KNDA), the official research and training institution for foreign service officers.
The Ministry of Foreign Affairs, which operates the academy, failed to detect the hack while it was underway, raising concerns about vulnerabilities in its cybersecurity capabilities. Critics say it also waited too long to notify employees about the leak.
The Foreign Ministry launched an investigation into the hack of the KNDA online education system, which lasted 10 months from April 2025 to early February 2026, after being informed by another government body in February. Data on the server included the names, user IDs, email addresses and encrypted passwords of individuals who had been trained at the KNDA.
The leaked records may include not only all diplomats working both at ministry headquarters and overseas but also agents from the National Intelligence Service and military attachés from the Ministry of National Defense who received training before overseas assignments.
“There were around 10,000 records saved on the server,” a Foreign Ministry official said on Tuesday. The official said the leak was “unprecedented” and admitted it was “not unrelated to national security.”
The ministry has not disclosed exactly who orchestrated the attack, although investigators are open to the possibility that it was the North Korean or Chinese government.
“At the present, our technical analysis hasn’t reached the point where we can assign responsibility. We’re open to all possibilities, including hacking organizations backed by other countries,” a ministry official said.
There are concerns that sensitive information about diplomats could be exploited for malicious purposes.
The hacked system was brought online in 2022, when in-person training was not feasible because of the spread of the coronavirus.
The ministry periodically assessed the system’s cybersecurity, but didn’t become aware of this attack until being notified by a relevant organization in early February.
“This attack was carried out with standard software authorization after accessing the system using a zero-day vulnerability, a weakness that software developers weren’t aware of. That made it difficult to detect using ordinary means,” the ministry official explained.
But even granting that hackers were using a novel technique, the ministry can hardly avoid criticism for failing to detect the attack for a full 10 months, as well as for not taking adequate precautions against hacking despite handling sensitive personal information related to national security.
The ministry has so far been unable to determine the extent of the damage, including how many records were leaked.
It was not until Monday, five months after the investigation was launched, that the ministry released its first press release about the hack.
So far, employees have only been given a notice on the website. The ministry plans to notify affected employees personally.
It’s unknown exactly when the foreign minister and the National Security Office at the Blue House were briefed about the leak.
“We’re taking this incident very seriously, and we’ll work with the relevant organizations to fully account for what happened,” ministry spokesperson Park Il said.
“We view this incident as an opportunity to overhaul our internal cybersecurity system by addressing shortcomings and bolstering our management system,” he noted.
By Park Min-hee, senior staff writer
Please direct questions or comments to [[email protected]]