Skip to main content
Security

South Korea Korea National Diplomatic Academy Data Breach Exposes Diplomat Information via Zero-Day Vulnerability

South Korea Korea National Diplomatic Academy Data Breach Exposes Diplomat Information via Zero-Day Vulnerability Image: Primary
South Korea has disclosed a significant data breach impacting the Korea National Diplomatic Academy's online education system exposing personal information of current and former Ministry of Foreign Affairs employees including overseas diplomats. The breach was facilitated by the exploitation of a previously unknown vulnerability in the Academy's server. The breach remained undetected for approximately ten months from April 2025 to expose personal information of current and former Ministry of Foreign Affairs employees including overseas diplomats. The breach was discovered by the National Intelligence Service in February 2026 after the system had been compromised via a zero-day vulnerability from April/May 2025 until February 2026. Public disclosure of the incident occurred on July 21-22, 2026, following internal review and analysis. The compromised data includes names user IDs email addresses encrypted passwords positions and departmental affiliations of up to 10,000 individuals with at least 6,000 confirmed affected and 350 being current government attachés. No sensitive identification numbers mobile phone numbers home addresses or internal government systems were compromised.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from rescana.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Products
Security Products

Liquid sidechain pauses after reported 4,000 BTC withdrawal

Liquid says purported white-hat hackers withdrew about 4,000 BTC, valued in its statement at roughly $320 million, from the Liquid Federation wallet. The company says the funds left through the SideSwap Peg-out Authorization Key, ...

Security Policy
Security Policy

Berlin reviews ransomware data release after rejecting ransom

Berlin's state government said it is reviewing a 5.79TB trove of stolen data published by the Rhysida ransomware group after the state refused to pay a ransom. Reuters reported that the released files reportedly include national-d...

Security Infrastructure
Security Infrastructure

JetBrains tells Cadence users to rotate credentials after TeamCity breach

JetBrains is telling Cadence users to revoke or rotate credentials and secrets after attackers exploited a critical TeamCity vulnerability to breach a Cadence environment. The company said the attackers accessed a 2024 server back...

Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...