The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy’s online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas.
According to the Ministry of Foreign Affairs, the attackers exploited a vulnerability in the National Diplomatic Academy’s online education platform in April 2025. The compromise remained active until February 2026, allowing unauthorized access to data linked to thousands of individuals before the incident was eventually discovered and contained.
National Diplomatic Academy Data Breach Remained Active for Nearly 10 Months
The National Diplomatic Academy data breach began in April 2025 after an unidentified threat actor exploited a security flaw in the academy’s online education system. The platform, which was introduced in 2022 to support remote learning during the COVID-19 pandemic, has since been used for government employee training and video conferencing.
According to the Ministry of Foreign Affairs, personal information was exposed between April 2025 and February 2026.
In an official announcement, the ministry stated:
There was an unidentified attack exploiting a security vulnerability targeting the Korea National Diplomatic Academy’s online education system, and it has been confirmed that personal information of former and current employees of the Ministry of Foreign Affairs headquarters and overseas missions, as well as other personnel, was leaked from April 2025 to February 2026.”

The ministry said the attack affected current and former employees at its headquarters, overseas missions, and other personnel connected to the online education system.
Thousands Impacted in South Korea Foreign Ministry Data Breach
The National Diplomatic Academy data breach is estimated to have impacted at least 6,000 individuals, including approximately 350 government attachés currently stationed abroad. However, reports from Korean media suggest the number of affected individuals could be as high as 10,000, while other reports indicate lower figures.
In addition to personal information, local media reported that official job titles and departmental affiliations may also have been exposed during the incident.
The Ministry of Foreign Affairs has not confirmed the higher estimates but acknowledged that the breach affected a substantial number of current and former personnel associated with the diplomatic service.
What Information was Exposed?
According to the Ministry of Foreign Affairs, the information compromised during the National Diplomatic Academy data breach included:
- User IDs
- Names
- Email addresses
- Encrypted passwords
The ministry emphasized that several categories of sensitive information were not exposed.
Its official notice stated:
“The personal information items involved in the leak include the ID, name, email, and encrypted password of the trainee in the Korea National Diplomatic Academy’s online education system.”
The notice further clarified:
“Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not included.”
This means national identification numbers, photographs, residential addresses, phone numbers, and other sensitive personal data were not part of the compromised dataset, according to the ministry.

