Drooid Logo
Back to story perspectives

Full Breakdown

South Korea Probes Cyberattack on Diplomatic Academy Amid Possible North Korean Link

7/21/2026, 12:58:57 PM

Core Event

South Korea’s Foreign Ministry announced on July 21 that a cyberattack on the Korea National Diplomatic Academy’s online education system exposed a “significant” amount of data. The breach exploited an unknown “zero-day” software vulnerability and weak security configurations, allowing attackers to control a server from April–May 2025 until February 2026, when suspicious activity was detected and the system was blocked. Authorities have not yet identified the full scope of the leak or the specific information compromised.

Data & Statistics

  • The academy’s platform stored training videos, course-administration details, participants’ names and user IDs.
  • Dong-A Ilbo, citing government sources, reported that personal information of roughly 6,000 current and former diplomats and officials seconded from other ministries may have been compromised.

Official Statements & Responses

Ministry spokesperson Park Il told a briefing that the leak was of “considerable scale” but that “no misuse of leaked data had been confirmed.” He added that investigators have “insufficient technical evidence to determine who was behind the attack,” while emphasizing that the government is not ruling out any possibilities, including foreign-based hacking groups. The ministry said it is working with relevant agencies to assess the breach’s full extent and to strengthen internal cybersecurity systems.

Verbatim Quotes

  • “considerable scale” — Park Il, Ministry spokesperson

Conflicting Reports & Gaps

  • While South Korean officials have not confirmed any data misuse, intelligence authorities are investigating whether a North Korean-linked hacking group targeted the academy.
  • The exact categories of compromised information remain unclear, and technical analysis of the zero-day exploit has not been publicly disclosed.

The investigation continues as Seoul seeks to delineate the breach’s impact and to fortify its diplomatic-training infrastructure against future cyber threats.