
South Korea revealed a 10-month cyber breach of its National Diplomatic Academy’s training system, exposing personal data of nearly all diplomats and other Foreign Ministry personnel.
The Korea National Diplomatic Academy (KNDA) is South Korea’s premier diplomatic training institute under the Ministry of Foreign Affairs. It is responsible for training new foreign service officers, providing ongoing education for diplomats and ministry staff, and conducting research on diplomacy and international affairs.
Recently, South Korea’s Ministry of Foreign Affairs disclosed that threat actors exploited a security vulnerability in the Korea National Diplomatic Academy’s (KNDA) online education system. The breach, which lasted from April 2025 to February 2026, resulted in the exposure of personal information belonging to current and former Ministry of Foreign Affairs headquarters staff, overseas mission employees, and other personnel.
The compromised data included user IDs, names, email addresses, and encrypted passwords of individuals enrolled in the KNDA’s online education system. The Ministry, however, said that the sensitive personal information such as unique identification numbers, mobile phone numbers, home addresses, and photographs were not affected.
In a statement shared with Korean media, a ministry official said, “About 10,000 sets of data were stored on the system. We are assuming that a significant amount was leaked, although it remains difficult to determine the exact scale.”
In response to the incident, the Ministry of Foreign Affairs said access to the compromised online education system has been blocked to contain the breach and prevent further unauthorised activity. Also additional security measures, including strengthening system protections, enhancing monitoring capabilities, and conducting a comprehensive security review to reduce the risk of future cyber attacks has been implemented.
Ministry officials said the investigation to identify the threat actors responsible for the breach is ongoing and is expected to take time. They also explained that disclosure of the incident was delayed due to the complexity of analyzing the compromised server and the need for caution, as the breach involved a large volume of personnel data with potential national security implications.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543