ctipilot.ch
← Back to the live brief
NOTABLENATOB2incident

South Korea's Foreign Ministry: a ~10-month zero-day intrusion into the Diplomatic Academy's e-learning platform exposed records on nearly all diplomats

discovered 2026-07-22 04:34 UTCrun 2026-07-22T0409Z-intel3 sourcesmulti-source

South Korea's Ministry of Foreign Affairs disclosed on 2026-07-21 that attackers exploited a previously unknown zero-day in the server software behind the Korea National Diplomatic Academy's (KNDA) online training/e-learning platform, combined with security-configuration weaknesses, to seize control of the server between April and May 2025 (The Korea Herald, 2026-07-21). The intrusion evaded the Academy's routine security checks (in place since the platform's 2022 deployment) and was only discovered in early February 2026, after another government agency flagged suspicious activity; the server was then taken offline and the (unnamed) software vendor released a patch once the flaw was identified during the investigation. Public disclosure followed roughly five months after internal discovery.

Exposed data covers up to ~10,000 records of current and former diplomats, overseas-mission officials and embassy/consulate administrative staff — including names, user IDs, email addresses and encrypted passwords, but not resident-registration numbers, phone numbers, home addresses or photographs (DailySecu, 2026-07-21; Seoul Shinmun, 2026-07-22). Officials say there is not yet sufficient technical evidence to attribute the intrusion but have not ruled out state-backed groups, including North Korea.

The attacker exploited a previously unknown security flaw, known as a zero-day vulnerability, in software used by the platform

There is not yet enough technical analysis to determine the perpetrator

The Korea Herald 2026-07-21

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.