Skip to main content
Back to overview
High

South Korean Diplomatic Academy Suffers Significant Data Leak Affecting 10,000 Diplomats

On July 21, 2026, the Korea National Diplomatic Academy, an institution affiliated with South Korea's Ministry of Foreign Affairs, confirmed a significant data leak impacting approximately 10,000 records of current and…

Key points

  • The data leak affected approximately 10,000 records of current and retired South Korean diplomats.
  • The breach occurred in the online education system of the Korea National Diplomatic Academy.
  • An unidentified attacker exploited a zero-day vulnerability and maintained access from April-May 2025 to February 2026.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Vulnerability Exploitation

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Jul 21, 2026
Updated
Jul 23, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch internet-facing systems, credential abuse and exploit activity.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

YonseiData DisclosureSouth Korean Diplomatic Academy SuffersDiplomats On JulyKorea National Diplomatic AcademySouth KoreaMinistry of Foreign AffairsIDsWhileThe Foreign Ministry

Quick context

Questions about this signal

What happened in this signal?

On July 21, 2026, the Korea National Diplomatic Academy, an institution affiliated with South Korea's Ministry of Foreign Affairs, confirmed a significant data leak impacting approximately 10,000 records of current and retired diplomats. The breach, which occurred in the academy's online education system, was discovered in early February 2026 after suspicious access was reported by a government agency. An unidentified attacker exploited a zero-day vulnerability in the server software and weaknesses in system security settings, maintaining unauthorized access from April to May 2025 until February 2026. The compromised data reportedly included names, user IDs, email addresses, encrypted passwords, job titles, and affiliated departments. While sensitive personal information such as resident registration numbers, mobile phone numbers, and home addresses were not present on the affected server, the leak of diplomat information raises concerns, especially given that the full list of diplomats and personnel at overseas missions is not publicly disclosed. The Foreign Ministry is investigating the incident and has urgently shut down the compromised system. They are operating under the assumption that a substantial volume of data was compromised, though the exact scale of the damage is still being assessed. The incident highlights the challenges in detecting sophisticated attacks that leverage previously unknown vulnerabilities.

When was this signal reported?

Shadow Tier lists Jul 21, 2026 as the signal date.

Which organization is connected to this signal?

Yonsei is the organization connected to this public signal.

Explore Yonsei
Which attack pattern is relevant?

This signal is connected to vulnerability-exploitation intelligence based on its reported incident context.

Explore vulnerability-exploitation intelligence
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence