When Was Washington Notified?


The Foreign Ministry’s Five Months of Silence and the Continuing Threat to U.S. Counterintelligence
by Jean CummingsCo-Editor-in-Chief and Senior Columnist, The Korea Signal
“This special report examines the implications for U.S. national security of the large-scale exposure of information belonging to as many as 10,000 South Korean diplomatic and national security personnel, including hundreds of intelligence officers, and the South Korean government’s failure to disclose the incident for approximately five months. It traces how the breach may have created risks for the U.S. government, military and intelligence personnel, and the U.S.–ROK intelligence-sharing network, and explains why Washington should treat the incident as a major counterintelligence crisis.”
On July 20, 2026, South Korea’s Ministry of Foreign Affairs disclosed that the online training system operated by the Korea National Diplomatic Academy had been compromised for an extended period, resulting in the exposure of information belonging to diplomatic and national security personnel. South Korean authorities are investigating the possibility of a state-sponsored operation, including potential North Korean involvement, but the attacker has not yet been officially identified. The hacker gained control of the server sometime between April and May 2025 and maintained access to the system for approximately ten months, until February 2026. According to the Ministry of Foreign Affairs, the attacker exploited both a zero-day vulnerability—one that even the software developer did not know existed at the time—and deficiencies in the system’s security configuration. The attacker then used legitimate software privileges to remain active inside the system for an extended period.
The system contained the names, user IDs, email addresses, encrypted passwords, duty stations, and official positions of Foreign Ministry headquarters personnel, diplomats serving at overseas missions, officials seconded from other government ministries, administrative employees at diplomatic missions, and some intelligence officers deployed abroad. It also stored online training materials and information related to course assignments and participation. As many as 10,000 people may have been affected. Reports indicate that the exposed personnel included several hundred intelligence officers serving overseas under official diplomatic or government cover.
This incident cannot be treated merely as a breach involving the personal information of South Korean government employees. It is a serious matter with potentially grave consequences for the national security of the United States. South Korean diplomats and intelligence officers are the officials who conduct the day-to-day work of the U.S.–ROK alliance across the U.S. government, the armed forces, the intelligence community, Congress, defense contractors, and Washington think tanks. The simultaneous exposure of their names, duty stations, positions, and contact information means that an outside actor may now be able to trace the human network through which diplomatic and national security business between the United States and South Korea is actually conducted.
Washington’s first question should not be limited to which categories of personal information were compromised. The United States must first determine whether the attacker can cross-reference the stolen names, official positions, duty stations, and email addresses with publicly available information; identify individual South Korean diplomats and intelligence officers; trace the U.S. officials and institutions with which they have maintained contact; and impersonate those individuals in order to approach personnel at the Department of State, the Department of Defense, the U.S. intelligence community, and Congress.
The Attacker Can Construct a Map of the South Korean Government’s Overseas Personnel
A list containing only names and email addresses would already be sufficient to launch phishing attacks. Once official positions and duty stations are added, however, the nature of the data changes. What was once a contact list becomes a map of the South Korean government’s overseas personnel deployment. From that information, an attacker can identify which diplomats in Washington handle political and national security matters, which officials deal directly with the Department of Defense and U.S. Forces Korea, and which personnel are assigned to the United Nations and NATO. By comparing the stolen records with publicly available information from individual ministries, the attacker can also isolate officials responsible for semiconductors, export controls, defense procurement, North Korea sanctions, and North Korean human rights.
When embassy websites, Foreign Ministry personnel announcements, and records of congressional and think tank events are added, each individual’s actual responsibilities and range of U.S. contacts become considerably clearer. An attacker may be able to determine which bureau of the State Department a particular diplomat meets with regularly, who coordinates with the White House National Security Council, and which official works with the Pentagon on extended deterrence and combined military exercises. Intelligence officers assigned abroad under official diplomatic or government titles may also be classified by tracing publicly available personnel records and event attendance.
You are unauthorized to view this page. Please log in to read this page in full.
이 페이지를 보실 권한이 없습니다. 이 글 전문과 한글 버전을 읽으시려면 로그인을 먼저 해주십시오.
Please renew your membership or subscribe a membership if you didn't yet. Thank you.
멤버십을 갱신하시거나, 만약 구독하지 않으셨다면 구독을 먼저 해주시기 바랍니다. 감사합니다.
정기구독 신청하기 ← click here to subscribe. 여기를 클릭해서 구독해 주세요.




👍👍👍