Ministry of Foreign Affairs data of 10,000 diplomats, officials hacked for 10 months
Translated from Korean, summarized and contextualized by DistantNews.
At a glance
- The Ministry of Foreign Affairs' online education system server was hacked for 10 months, potentially exposing data of up to 10,000 diplomats and public officials.
- The compromised data includes names, IDs, email addresses, and encrypted passwords, but not resident registration numbers or phone numbers.
- The ministry is investigating the extent of the breach and has not ruled out the possibility of state-sponsored hacking groups, including those linked to North Korea.
The Ministry of Foreign Affairs is investigating a significant security breach where its online education system server was hacked for approximately 10 months. The system, managed by the National Diplomatic Academy, potentially exposed the personal information of up to 10,000 diplomats and public officials who used the platform for training.
This is an unprecedented event and a matter related to national security, which we are taking very seriously.
The breach, which occurred from April of last year to early February of this year, involved data stored on the server. According to ministry officials, the compromised information includes names, user IDs, email addresses, and encrypted passwords. Crucially, sensitive data such as resident registration numbers and mobile phone numbers were reportedly not stored on the system, mitigating some of the potential damage.
The data stored on the system included information on foreign affairs officials, personnel stationed at overseas missions, including attachรฉs and administrative staff.
Officials described the incident as an unprecedented event with national security implications, emphasizing its seriousness. While the exact number of affected individuals is still being determined, estimates suggest a substantial portion of the 10,000 records stored could have been leaked. The ministry is working to ascertain the precise scale of the data exfiltration.
Names, IDs, email addresses, and encrypted passwords were included, but resident registration numbers and mobile phones were not stored.
Regarding the perpetrators, the ministry stated that all possibilities are being considered, including hacking organizations potentially backed by other nations. While acknowledging the possibility of North Korean involvement, officials noted a lack of definitive technical evidence to confirm this. The delay in public disclosure, from the detection of the issue in February to the announcement, was attributed to the sensitive nature of the case and the need for thorough review and containment measures.
We are not ruling out any possibilities, including hacking organizations backed by other countries.
Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.