Executive Summary
South Korea has disclosed a significant data breach impacting the Korea National Diplomatic Academy's online education system, resulting in the exposure of personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. The breach, which remained undetected for approximately ten months from April 2025 to February 2026, was facilitated by the exploitation of a previously unknown (zero-day) vulnerability in the Academy's server. The compromised data includes names, user IDs, email addresses, encrypted passwords, positions, and departmental affiliations of up to 10,000 individuals, with at least 6,000 confirmed affected and 350 being current government attachés. No sensitive identification numbers, mobile phone numbers, home addresses, or internal government systems were compromised. The breach was discovered by the National Intelligence Service in February 2026, after which the affected system was shut down and an investigation was initiated. As of July 2026, no technical indicators or attribution to a specific threat actor have been disclosed, and the investigation remains ongoing.
Technical Information
The breach targeted the Korea National Diplomatic Academy's online education platform, which was established in 2022 to facilitate remote training and video conferencing for government personnel during the COVID-19 pandemic. The platform was internet-facing and stored personal data for a wide range of users, including diplomats, administrative staff, and officials from other government agencies posted to overseas missions.
Attack Vector
The initial compromise occurred via exploitation of a zero-day vulnerability in the education platform's software. This vulnerability was unknown to both the software manufacturer and security authorities at the time of the breach, and was only identified during the post-incident investigation. The attacker maintained persistent, undetected access to the system for approximately ten months, from April/May 2025 until February 2026. The compromised server was located inside MFA headquarters and was excluded from regular security scrutiny, which contributed to the prolonged dwell time.
Data Compromised
The attacker accessed a database containing approximately 10,000 personnel records. The compromised data includes names, user IDs, email addresses, encrypted passwords, positions, and departmental affiliations. No resident registration numbers, mobile phone numbers, home addresses, photographs, or government employee identification numbers were stored on the affected server. The system was also isolated from the ministry’s internal network, passport system, and other sensitive government networks, and there is no evidence that the attacker gained access to these systems.
Detection and Response
The breach was discovered in early February 2026 by the National Intelligence Service, which notified the MFA of suspicious activity. The MFA subsequently shut down the online education system and began a joint investigation. The ministry delayed public disclosure of the incident until July 2026, citing the sensitive nature of the breach and the need for thorough analysis and review.
Technical Analysis and Attribution
No specific malware, tools, or technical indicators have been disclosed in relation to this incident. The only confirmed technical method is the exploitation of a zero-day vulnerability. There is no evidence of lateral movement, privilege escalation, or use of post-exploitation frameworks. Attribution remains undetermined, with officials stating that all possibilities, including foreign state-sponsored actors, are being considered. The use of a zero-day and the targeting of diplomatic personnel are consistent with advanced persistent threat (APT) activity, but there is no direct evidence linking this incident to any known group.
MITRE ATT&CK Mapping
The attack aligns with the following MITRE ATT&CK techniques: - Initial Access: Exploit Public-Facing Application (T1190) – High confidence, based on explicit statements from all sources. - Collection: Data from Information Repositories (T1213) – Medium confidence, based on the nature of the data accessed. - Defense Evasion: Exploit Public-Facing Application (T1190) – High confidence, as the zero-day bypassed standard detection. - Exfiltration: Exfiltration Over Web Service (T1567) – Low confidence, as the exfiltration method is not explicitly confirmed.
Sector-Specific Implications
The breach has significant implications for the diplomatic sector, exposing the identities, roles, and contact information of diplomats and government officials. This increases the risk of spear-phishing, social engineering, and further targeting of affected individuals. While no sensitive government systems were compromised, the exposure of personnel data presents potential national security risks.
Affected Versions & Timeline
The affected system is the Korea National Diplomatic Academy's online education platform, launched in 2022. The breach timeline is as follows: attackers gained access via a zero-day vulnerability in April/May 2025 and maintained undetected access until February 2026. The breach was discovered by the National Intelligence Service in early February 2026, at which point the system was shut down and an investigation commenced. Public disclosure occurred on July 21–22, 2026, following a period of internal review and analysis.
Threat Activity
The threat actor exploited a previously unknown vulnerability in the education platform’s software, enabling persistent access to the system for ten months. The attacker repeatedly accessed the server and exfiltrated data from the personnel database. No specific malware, tools, or infrastructure have been identified or disclosed. The attacker’s identity and motives remain unknown, and no attribution has been made. The use of a zero-day and the focus on diplomatic personnel suggest a sophisticated actor, but this remains unconfirmed.
Mitigation & Workarounds
The following mitigation steps have been implemented or are recommended, prioritized by severity:
Critical: Immediate shutdown of the compromised online education system and isolation from other government networks. Application of security patches to address the exploited zero-day vulnerability, as released by the software manufacturer. Comprehensive forensic investigation of the affected system and review of all related logs to identify the scope of the breach.
High: Notification and guidance to potentially affected individuals, including advice to monitor for suspicious communications and report any incidents to the ministry’s security department. Enhanced security reviews and regular vulnerability assessments for all internet-facing systems, especially those handling sensitive personnel data.
Medium: Review and update of incident response plans and communication protocols for sensitive breaches. Implementation of additional monitoring and detection controls for systems excluded from regular security scrutiny.
Low: Ongoing evaluation of the need to resume or replace the affected online education platform, with consideration for improved security architecture and user authentication mechanisms.
Indicators of Compromise
No public indicators of compromise were available at the time of writing.
References
BleepingComputer, July 22, 2026: https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/amp/
UPI, July 21, 2026: https://www.upi.com/amp/Top_News/World-News/2026/07/21/korea-Korean-diplomats-personal-information-leaked-data-breach/5201784624121/
Korea Herald, July 21, 2026: https://www.koreaherald.com/article/10815199
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor risks in their digital supply chain. Our platform enables continuous security assessments, supports incident response workflows, and facilitates evidence-based risk analysis for systems handling sensitive data. For questions or further information, please contact us at info@rescana.com.



