ctipilot.ch

KNDA diplomatic-academy zero-day breach

incident · incident:south-korea-knda-diplomatic-academy-zero-day-breach-2026

Korea National Diplomatic Academy's online training/e-learning platform compromised via an undisclosed zero-day plus security misconfiguration (April/May 2025 – February 2026 dwell); up to ~10,000 diplomat and embassy-staff records exposed; attribution unconfirmed, state-backed groups incl. North Korea not ruled out (Korea Herald, DailySecu, Seoul Shinmun, 2026-07-21/22).

Coverage timeline
1
first 2026-07-22 → last 2026-07-22
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-22/south-korea-knda-elearning-zero-day-breach · ATT&CK page ↗

Story timeline

  1. 2026-07-22South Korea's Foreign Ministry: a ~10-month zero-day intrusion into the Diplomatic Academy's e-learning platform exposed records on nearly all diplomats
    active-threatsAn overlooked externally-facing staff e-learning platform gave attackers a 10-month foothold into a G20 foreign ministry

Where this entity is cited

  • active-threats1

Source distribution

  • dailysecu.com1 (33%)
  • koreaherald.com1 (33%)
  • seoul.co.kr1 (33%)

explore in graph

Entries about KNDA diplomatic-academy zero-day breach (1)

2026-07-22 · view entry permalink →

NOTABLENATOB2

South Korea's Foreign Ministry: a ~10-month zero-day intrusion into the Diplomatic Academy's e-learning platform exposed records on nearly all diplomats

South Korea's Ministry of Foreign Affairs disclosed on 2026-07-21 that attackers exploited a previously unknown zero-day in the server software behind the Korea National Diplomatic Academy's (KNDA) online training/e-learning platform, combined with security-configuration weaknesses, to seize control of the server between April and May 2025 (The Korea Herald, 2026-07-21). The intrusion evaded the Academy's routine security checks (in place since the platform's 2022 deployment) and was only discovered in early February 2026, after another government agency flagged suspicious activity; the server was then taken offline and the (unnamed) software vendor released a patch once the flaw was identified during the investigation. Public disclosure followed roughly five months after internal discovery.

Exposed data covers up to ~10,000 records of current and former diplomats, overseas-mission officials and embassy/consulate administrative staff — including names, user IDs, email addresses and encrypted passwords, but not resident-registration numbers, phone numbers, home addresses or photographs (DailySecu, 2026-07-21; Seoul Shinmun, 2026-07-22). Officials say there is not yet sufficient technical evidence to attribute the intrusion but have not ruled out state-backed groups, including North Korea.

The attacker exploited a previously unknown security flaw, known as a zero-day vulnerability, in software used by the platform

There is not yet enough technical analysis to determine the perpetrator

The Korea Herald 2026-07-21
incident22 Jul 04:34Zmulti-sourceOpen finding ↗