South Korea Discloses Data Breach Impacting Diplomats Worldwide
South Korea’s government has disclosed that attackers breached the online education system run by the country’s National Diplomatic Academy and remained inside the network for roughly ten months before being discovered. The academy trains and certifies career diplomats, and its e-learning platform held personal records tied to current and former staff of the Ministry of Foreign Affairs.
According to the disclosure, the data taken includes personal information belonging to diplomats posted at South Korean missions around the world, as well as former ministry employees, raising concerns about the exposure of individuals serving in sensitive overseas roles. The long dwell time — nearly a year before detection — suggests the intrusion may have gone unnoticed through standard monitoring, a recurring problem in breaches involving training or administrative systems that sit outside an organization’s most closely watched core networks.
The ministry has not publicly attributed the intrusion to a specific threat actor. Breaches of diplomatic personnel data are particularly sensitive because stolen identity and contact information can be used for follow-on targeting, including espionage-linked phishing campaigns against the individuals named in the stolen records.
This summary is based on reporting from BleepingComputer; further detail on the scope of the breach and any notification process for affected individuals may emerge as the investigation continues.