South Korea discloses wide-ranging diplomatic data breach
South Korea’s Ministry of Foreign Affairs has disclosed a large-scale cyberattack that compromised the personal data of nearly all employees across its diplomatic network, raising concerns about potential national security risks.
The breach, reported by the Korea JoongAng Daily, targeted the Korea National Diplomatic Academy (KNDA), the institution responsible for training the country’s diplomatic personnel. According to the ministry, attackers gained access to a server supporting the academy’s training platform in mid-2025 and retained control of the system for approximately ten months.
The intrusion was identified by South Korea’s National Intelligence Service in February, but authorities only publicly confirmed the incident on July 21.
Officials said that approximately 10,000 records were exposed in the breach. The compromised data includes employee names, user identification numbers, email addresses, encrypted passwords, as well as information detailing individuals’ positions and departmental affiliations.
The ministry assessed that the leak affected virtually the entire central apparatus of the foreign ministry, as well as personnel stationed at South Korean diplomatic missions abroad.
In a statement, the ministry warned that the scale and nature of the breach could pose a threat to national security, noting that overseas diplomatic missions include not only civilian diplomats but also military attachés and intelligence personnel.
Cybersecurity experts have suggested that North Korean hacking groups could be behind the attack, although South Korean authorities emphasised that the investigation remains ongoing and that no official attribution has yet been made.
By Tamilla Hasanova







