South Korea MFA Breach: Diplomat Data Exposed 10 Months
South Korea's MFA confirmed a ten-month breach of the National Diplomatic Academy, exposing personal data of current and former diplomats worldwide.
Breach confirmed. South Korea’s Ministry of Foreign Affairs (MFA) disclosed that attackers breached the National Diplomatic Academy’s online education platform and maintained access for ten months. Personal information belonging to current and former MFA employees — including overseas diplomats stationed worldwide — was extracted. Confidence: confirmed by the South Korean government, as reported by BleepingComputer on July 22, 2026.
What was accessed
Target: The National Diplomatic Academy’s online learning system — a secondary educational and training platform for MFA personnel. Not core diplomatic communications infrastructure. Confidence: confirmed per disclosure.
Affected population: Current and former Republic of Korea MFA employees, including overseas diplomatic staff worldwide. Confidence: confirmed per disclosure. Total count of affected individuals: not yet publicly stated.
Data type: Personal information. Specific field categories — whether contact details, passport data, assignment history, or anything beyond basic PII — have not been detailed in public statements as of this writing. Confidence: category confirmed, exact scope unconfirmed.
Access duration: Ten months. Whether that was continuous persistence or repeated re-entry across the window is not stated. Confidence: duration as-stated by government disclosure.
Attribution
None. No threat actor has claimed responsibility. South Korean authorities have not published attribution as of this writing.
Ten months of undetected access to a platform hosting diplomatic personnel data has obvious intelligence value — that framing is analytical, not evidenced. File it as context. Unconfirmed. Treat accordingly.
Prior nation-state campaigns targeting APAC diplomatic personnel have used persistent, low-noise access to build personnel dossiers over time — see the Kaspersky GoSerpent / TetrisPhantom overlap report from last week for one data point. No link between that activity and this breach is established.
Unconfirmed as of publication — treat accordingly
- Total number of individuals affected across all diplomatic posts.
- Exact data types within “personal information.”
- Initial access method.
- Whether the compromised system is now secured or still under investigation.
- Whether any extracted data has been observed in use downstream.
For those in the affected population
If you are a current or former employee of the Republic of Korea’s Ministry of Foreign Affairs, or served in an overseas diplomatic posting: treat your personally identifiable information as compromised.
Targeted spear-phishing using accurate personal details is the most immediate risk. Contact attempts that reference your posting history, assignment details, or internal personnel data should be treated as hostile until confirmed otherwise. Report them.
Sources
- BleepingComputer, 2026-07-22: South Korea discloses data breach impacting diplomats worldwide
Confidence summary: Breach confirmed by South Korean government disclosure. Target system: National Diplomatic Academy online education platform, confirmed. Access duration: ten months, as-stated. Affected population: current and former MFA employees and overseas diplomats, confirmed. Exact data scope and total affected count: unconfirmed. Attribution: none published.
Found this useful? Share it.


