Circuit Wire — a daily news update from the Circuit.

South Korea's Foreign Ministry has disclosed that hackers sat inside the Korea National Diplomatic Academy's online training system for about ten months, exposing personal data tied to current and former diplomats and staff.

The ministry said the intrusion began in April 2025 and ran until February 2026 before it was detected. The academy launched the platform in 2022 to deliver remote job training and language courses for diplomatic personnel.

The stolen records include usernames, real names, email addresses, and encrypted passwords, according to the ministry. Resident registration numbers, phone numbers, home addresses, and photos were not part of the leak. The daily Dong-A Ilbo reported that data on roughly 10,000 current and former diplomats and seconded officials may have been compromised.

Investigators said the attackers exploited a previously unknown, or zero-day, flaw in the academy's server. South Korean officials have not named a culprit, though security researchers noted the method matches tactics linked to North Korean state-backed groups.

Foreign Ministry spokesperson Park Il said the ministry recognized the breach in February but waited five months to make it public. "We announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs," Park said.

The ministry has taken the platform offline, added security measures, and warned users to treat unexpected emails with caution. The case adds to a run of intrusions aimed at the systems that hold data on diplomats and officials posted abroad, a standing concern for organizations that move people through higher-risk regions.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

Keep Reading