Illustration = Jeong Da-un

The Korea National Diplomatic Academy under the Ministry of Foreign Affairs was subjected to prolonged cyberattacks by external forces, leading to a massive leak of personal data.

According to the Ministry of Foreign Affairs on the 21st, the Korea National Diplomatic Academy's online education system server was under the control of an unidentified hacker for a long period. The unidentified attacker exploited an undisclosed software security flaw (zero-day vulnerability) and lax system security settings to break in. After seizing server administrator privileges between April and May last year, the intruder moved in and out of the system without any restrictions until February this year.

In the process, the personal information—such as names, IDs, and affiliated titles—of about 6,000 people, including current and former diplomats working around the world and resident officers dispatched from other ministries to overseas missions, was widely exposed. There is a risk that the leaked list may even include some personal details of intelligence agency operatives who conceal their identities while working overseas, raising significant security concerns.

The Ministry of Foreign Affairs said, "This attack was difficult to detect through ordinary means because the intruder accessed the system by exploiting a zero-day vulnerability that even the software manufacturer was unaware of at the time and then used legitimate software privileges, and no security update was available at that point to remedy the issue, which limited our response."

The Ministry of Foreign Affairs has completely shut down the education network since early February, when it detected the intrusion, and has been conducting a detailed investigation for five months. The ministry added that while course videos and operational identifiers were stored on the server, at this stage it is difficult to determine precisely what materials leaked and to what extent.

※ This article has been translated by AI. Share your feedback here.