01Summary
Ministry spokesperson Park Il said on 21 July 2026 that a system holding about 10,000 records of current and retired diplomats had been compromised through a zero-day. The intrusion ran from April 2025 to February 2026. Exposed data includes usernames, names, email addresses and encrypted passwords. Resident registration numbers, phone numbers and addresses were not included. Analysts said the method resembled North Korean state tactics. The ministry took the system offline and said it would change diplomats' email addresses because of the phishing risk.
02Victims and impact
Countries affected
- South Korea
03Data exposed
Data types
- Usernames
- Names
- Email addresses
- Encrypted passwords
04Timeline
- 2025-04-01Intrusion begins (April 2025).
- 2026-02-28Intrusion ends (February 2026).
- 2026-07-21Foreign Ministry discloses the breach.
05Aftermath
Security improvements
- System taken offline
- Diplomats' email addresses to be changed
06Disclosure and media
Publishing organisations
- Bloomberg
- Korea JoongAng Daily
- Korea Herald
- Help Net Security
07Sources
References
- [1]Help Net Security: https://www.helpnetsecurity.com/2026/07/23/south-korea-diplomatic-academy-data-breach/
- [2]Korea JoongAng Daily: https://www.koreajoongangdaily.com/bilingual-news/ten-months-of-undetected-hacking-exposes-security-failures-kor/12785323









