[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgnpsHMv2svuw4zuJFIT7Q5m3GWCVT97cvXT7gUgBOQ0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":23,"source":24,"isVerified":4,"isSpamList":25,"isSensitive":4,"severity":26,"processingStatus":27,"logoUrl":28,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66996e971889961f4baa32","SouthKoreaForeignMinistry2025_2026","Güney Kore Dışişleri Bakanlığı 2025–2026 Data Breach","south-korea-foreign-ministry-2025-2026","mofa.go.kr",{"name":12,"sector":13,"country":14,"website":10},"Republic of Korea Ministry of Foreign Affairs","Government","South Korea","2025-04-01T00:00:00.000Z","2026-07-26T23:34:06.980Z",0,[19,20,21,22],"User IDs","Names","Email addresses","Encrypted passwords","\u003Cp>\u003Cstrong>The South Korean Ministry of Foreign Affairs 2025–2026 data breach\u003C\u002Fstrong> occurred when an unknown actor exploited a security vulnerability in the Korea National Diplomatic Academy's online education system, exposing personal information associated with current and former ministry staff and other users. The ministry's official notice confirms indications of leakage over a period running from April 2025 through February 2026.\u003C\u002Fp>\n\u003Cp>The primary source is the South Korean Ministry of Foreign Affairs' official notice dated July 20, 2026. BleepingComputer and Korea JoongAng Daily independently reported the government announcement and press briefings. The official record lists education-system user IDs, names, email addresses, and encrypted passwords. Because no exact de-duplicated person total was published, LeakData does not use an unverified figure as pwnCount.\u003C\u002Fp>\n\u003Ch2>Compromised System and Data\u003C\u002Fh2>\n\u003Cp>The target was the online education system of the Korea National Diplomatic Academy, an institution affiliated with the Ministry of Foreign Affairs. The platform was established for remote training in 2022 and later used for government-personnel education and video conferencing. The official notice says an unidentified attack exploited a vulnerability and produced evidence of leakage involving headquarters staff, overseas missions, former employees, and other personnel.\u003C\u002Fp>\n\u003Cp>The directly confirmed data classes are user IDs, names, email addresses, and encrypted passwords. Korea JoongAng Daily, citing a senior ministry official, also reported that official job titles and departmental affiliations appeared in the approximate record inventory, but LeakData limits the formal classes to the four fields explicitly enumerated in the public ministry notice. “Encrypted” does not mean that passwords were disclosed as plaintext.\u003C\u002Fp>\n\u003Ch2>Ten-Month Timeline\u003C\u002Fh2>\n\u003Cp>The ministry placed the leakage period between April 2025 and February 2026 without publishing an exact first-access day. LeakData uses April 1, 2025, the beginning of the verified month-level window, as the breach date. This is not a claim that the actor entered on that precise day; it is the narrowest public starting boundary. News reporting says access continued intermittently for roughly ten months.\u003C\u002Fp>\n\u003Cp>According to the reports, South Korea's National Intelligence Service detected unusual activity in February 2026, alerted the ministry, and the system was shut down. The ministry disclosed the event publicly in July. Spokesperson Park Il said diplomatic and security sensitivity and the need for careful analysis accounted for the five-month delay. Detection, technical review, and public notification are therefore separate stages.\u003C\u002Fp>\n\u003Ch2>Why the Affected-Person Count Is Unknown\u003C\u002Fh2>\n\u003Cp>BleepingComputer reported that at least 6,000 people were affected, including 350 current government attachés posted abroad. Korea JoongAng Daily, citing officials, described an inventory of approximately 10,000 data entries. That report explicitly warns that 10,000 is not a confirmed unique-person count because the data may include duplicate entries and retained records for former personnel.\u003C\u002Fp>\n\u003Cp>Those measurements are not directly equivalent: one is a person estimate, while the other is a non-de-duplicated record inventory. The ministry's official web notice provides no exact total. LeakData therefore does not present either 6,000 as a definitive lower-bound counter or 10,000 as pwnCount; it keeps the person total unknown and explains the reported scale with its qualifications. Zero does not mean nobody was affected.\u003C\u002Fp>\n\u003Ch2>Diplomatic and Account-Security Risk\u003C\u002Fh2>\n\u003Cp>A combination of user ID, name, and email address can support convincing phishing messages tailored to a person's institutional role. Encrypted password data may be subjected to offline guessing depending on the algorithm and password strength. The finding that passwords were not plaintext therefore does not eliminate risk. Reuse of the same password on another system could increase the chance of secondary account compromise.\u003C\u002Fp>\n\u003Cp>The ministry said unique identification numbers, sensitive information, mobile phone numbers, home addresses, and photographs were not included. Those exclusions are reflected in the record. Because reporting places active diplomats and overseas missions within scope, the leak could support role-focused social engineering or personnel mapping; however, no public evidence confirms that the actor used the data for those purposes.\u003C\u002Fp>\n\u003Ch2>The Ministry's Response\u003C\u002Fh2>\n\u003Cp>The Ministry of Foreign Affairs blocked access to the online education system and said it implemented additional security-strengthening measures. Korea JoongAng Daily reported that personnel temporarily had to use in-person training or a separate government video-conferencing service. Technical analysis and work to identify the attacker were continuing at the time of public disclosure.\u003C\u002Fp>\n\u003Cp>The ministry did not attribute the attack to a state or named group. Although some analysts said the method resembled tactics used by state-backed actors, the spokesperson said there was not yet enough technical analysis to identify the culprit and no possibility had been excluded. LeakData does not label North Korea, Lazarus, Kimsuky, or another actor as confirmed; it records an unknown actor and verified exploitation of a vulnerability.\u003C\u002Fp>\n\u003Ch2>What Affected Personnel Should Do\u003C\u002Fh2>\n\u003Cp>The ministry advised particular caution with emails from unclear or unknown sources and recommended reporting suspicious communications to its security department. Affected users can replace the education-system password and any identical or similar password elsewhere with unique strong credentials, terminate existing sessions, and enable multi-factor authentication where supported. Password-reset links should be opened only through known official channels.\u003C\u002Fp>\n\u003Cp>This record documents prolonged unauthorized access to an education system and personal-data leakage; it does not claim that all classified diplomatic documents were stolen. The verified outcome is vulnerability exploitation from April 2025 through February 2026, exposure of IDs, names, emails, and encrypted passwords, and shutdown of the online system. The exact person count, actor, vulnerability details, and subsequent use of the data remain undisclosed.\u003C\u002Fp>","Online diplomatic education system breach",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fmofa_go_kr.png"]