South Korea’s Ministry of Foreign Affairs has revealed that a cyberattack targeting the Korea National Diplomatic Academy (KNDA) may have resulted in the exposure of a significant amount of sensitive data, with authorities investigating the possible involvement of foreign state-backed hackers.
Speaking at a media briefing on Tuesday, ministry spokesperson Park Il said preliminary findings indicate that the breach led to a data leak of “considerable scale.” However, officials are still assessing the full extent of the compromise and have not yet identified the exact type of information that may have been exposed.
Park stated that there is currently no evidence suggesting that any leaked information has been misused. He also noted that investigators do not yet have sufficient technical evidence to determine who carried out the attack, though authorities have not ruled out any possibility, including the involvement of foreign-backed hacking groups.
The update comes after the ministry disclosed on Monday that attackers exploited a previously unknown zero-day software vulnerability along with security configuration weaknesses to infiltrate the online education platform of the Korea National Diplomatic Academy.
According to the ministry, the attackers gained control of a server sometime between April and May 2025 and retained access until February 2026. The breach was discovered after suspicious activity was flagged by a government agency, prompting authorities to block the compromised system.
Officials said the affected platform contained educational content and administrative information required for course management, including participants’ names and user IDs. However, they added that it remains difficult to determine exactly what information was accessed or leaked during the intrusion.
Meanwhile, South Korean newspaper Dong-A Ilbo reported, citing government sources, that personal information belonging to nearly 6,000 current and former diplomats, as well as officials seconded from other ministries, may have been compromised.
The report further stated that intelligence agencies are examining whether a hacking group linked to North Korea could have been responsible for targeting data that includes information related to diplomats posted overseas.
Park reaffirmed that the ministry is coordinating with relevant government agencies to determine the full scope of the breach while also enhancing internal cybersecurity measures to prevent similar incidents in the future.