Skip to main content

Geographic intelligence

South Korea cybersecurity signals

Follow 1 current cybersecurity signal linked to South Korea through an affected location, a profiled company's country, or both, with source reporting.

Affected-country links use structured victim-country data. Company-country links use a reviewed profile based on the organisation's headquarters or the local operating entity represented by its domain. A signal linked in both ways is counted once in the total; actor origin and locations inferred from prose remain excluded.

🇰🇷

Country context

About Korea, Rep.

Reference details that help place the cybersecurity reporting in its geographic and economic context.

Region
East Asia & Pacific
Capital
Seoul
Income group
High income
ISO codes
KR / KOR
ISO numeric
410

1

Total linked signals

Linked through an affected location, company headquarters, or both.

Not classified

Signals affecting this country

Victim-country data is unavailable in this reporting window.

1

Signals from companies based here

Based on reviewed company headquarters.

1

High or critical

Severity classifications among linked signals.

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to South Korea through an affected location, a profiled company's country, or both. Counts describe this reporting set, not overall incident prevalence.

Company-linked signals

Current reporting linked to South Korea

High

South Korean Diplomatic Academy Suffers Significant Data Leak Affecting 10,000 Diplomats

On July 21, 2026, the Korea National Diplomatic Academy, an institution affiliated with South Korea's Ministry of Foreign Affairs, confirmed a significant data leak impacting approximately 10,000 records of current and retired diplomats. The breach, which occurred in the academy's online education system, was discovered in early February 2026 after suspicious access was reported by a government agency. An unidentified attacker exploited a zero-day vulnerability in the server software and weaknesses in system security settings, maintaining unauthorized access from April to May 2025 until February 2026. The compromised data reportedly included names, user IDs, email addresses, encrypted passwords, job titles, and affiliated departments. While sensitive personal information such as resident registration numbers, mobile phone numbers, and home addresses were not present on the affected server, the leak of diplomat information raises concerns, especially given that the full list of diplomats and personnel at overseas missions is not publicly disclosed. The Foreign Ministry is investigating the incident and has urgently shut down the compromised system. They are operating under the assumption that a substantial volume of data was compromised, though the exact scale of the damage is still being assessed. The incident highlights the challenges in detecting sophisticated attacks that leverage previously unknown vulnerabilities.

FAQ

Questions about South Korea cybersecurity signals

What is included on the South Korea page?

This page brings together current signals connected to South Korea through an affected location, a reviewed company profile, or both.

Does a signal prove the attacker is based in South Korea?

No. The country connection describes affected locations or profiled company locations. It does not claim actor origin unless a source explicitly establishes that separately.

Why can the number of signals change?

The page follows the rolling current-reporting window. Counts change as new incidents are added, evidence is reviewed, and older signals leave that window.