As the Korea National Diplomatic Academy under the Ministry of Foreign Affairs was attacked by an unidentified hacker, the Ministry of Foreign Affairs said it would actively cooperate with related agencies in their investigation and strengthen its internal security network. The incident is estimated to have leaked up to about 10,000 items of personal data, including information on Korean diplomats.
On the 21st, at a regular briefing held at the Ministry of Foreign Affairs building in Jongno-gu, Seoul, Park Il, Spokesperson for the Ministry of Foreign Affairs, said, "The Ministry of Foreign Affairs takes this matter very seriously and will work with related agencies to thoroughly determine the cause of the incident."
Park, the Spokesperson, added, "Taking this incident as an opportunity, the Ministry of Foreign Affairs will closely inspect its internal cybersecurity system to fix deficiencies and strengthen related management systems."
Earlier, the Ministry of Foreign Affairs said that the Korea National Diplomatic Academy under the ministry had been under cyberattack by external actors for an extended period, leading to a large-scale leak of personal information. The hacked server stored the names, IDs, email addresses, and encrypted passwords of people trained at the academy. It is currently estimated that 10,000 data items, including information on Korean diplomats, were taken.
The unidentified attacker appears to have broken in by identifying an undisclosed software security flaw (zero-day vulnerability) and lax system security settings.
The hacker is believed to have seized control of the server around Apr.–May last year and accessed it repeatedly through early Feb. this year. Although the hacking continued for about 10 months, the Ministry of Foreign Affairs reportedly did not recognize it until it was notified by a related agency.
The leaked information included the names, IDs, emails, and encrypted passwords of foreign service officials, resident officers from government ministries dispatched overseas, and administrative staff at overseas missions. However, sensitive information such as photos, resident registration numbers, mobile phone numbers, and addresses was not included.
The Ministry of Foreign Affairs said it has conducted multiple security inspections every year, including immediately after the system went live in 2022. However, it explained that because the attack exploited a newly discovered, previously unknown vulnerability, it was difficult to detect through existing inspections.
Regarding the fact that the Ministry of Foreign Affairs recognized the breach in early Feb. this year but posted a notice about it on its website only the day before, on the 20th, about five months later, Park, the Spokesperson, said it "considered the sensitivity of the matter, as it involves not only diplomatic but also security agencies."
The Ministry of Foreign Affairs is investigating various organizations, including North Korea, as possible perpetrators of the hacking. Park, the Spokesperson, said, "Technical analysis sufficient to identify the actor behind the cyberattack is currently lacking," but added, "The government is not ruling out any possibilities, encompassing external hacking groups, including those from other countries."