[SPECIAL REPORT II] Washington Can No Longer Rely on Seoul’s Explanations

Ten Months Inside the Korea National Diplomatic Academy, Five Months of Silence—and Now the Military Medical Information Network Has Been Breached

by Jean Cummings
Co-Editor-in-Chief and Senior Columnist, The Korea Signal

On July 20, 2026, South Korea’s Ministry of Foreign Affairs disclosed that the online education system of the Korea National Diplomatic Academy had been hacked, resulting in the large-scale exposure of information belonging to diplomatic and national-security personnel. The attacker entered the server sometime between April and May 2025 and maintained access until February 2026, remaining inside the system for approximately ten months. The Foreign Ministry said both a zero-day vulnerability and inadequate security configurations had been exploited.

The system contained the names, user IDs, email addresses, encrypted passwords, workplaces, job titles, training materials, and course records of Foreign Ministry headquarters staff, diplomats stationed at overseas missions, officials seconded from other government ministries, locally hired diplomatic personnel, and intelligence officers posted abroad. As many as 10,000 people may have been affected, including hundreds of intelligence officers posted to overseas missions in official capacities, creating a grave national-security crisis.

The Foreign Ministry said it was notified by a related government agency of abnormal access activity in early February 2026 and then shut down the system. Yet the incident was not disclosed until July 20, approximately five months later. Former and current diplomats and government attachés whose information may have been compromised were also reportedly not informed before the public announcement.

During the same period, unauthorized access was also discovered in a South Korean military medical information system, bringing the situation to the point where classified national-security information can no longer be left to the South Korean government’s explanations and internal investigations alone. In an official notice issued on May 15, 2026, the Armed Forces Medical Command acknowledged that an outsider had accessed the mobile medical image storage and transmission system used by six military hospitals. On July 23, the JoongAng Ilbo reported that an unauthorized individual had accessed approximately eight gigabytes of data and that a communications port that should have remained closed for security reasons had been exposed to outside access for several months.

Lists of South Korean diplomatic and intelligence personnel and the medical information of military service members were exposed through separate systems. The South Korean government failed to detect these intrusions at an early stage and, even after the incidents became public, has responded by downplaying them rather than treating them with the seriousness they demand or taking aggressive action. The government has yet to identify the attacker or determine the full extent of the damage, and the fact that the Foreign Ministry confirmed the National Diplomatic Academy intrusion but kept it from the public for approximately five months provides ample reason to suspect that the government is concealing something.

The United States must immediately launch an independent investigation to determine whether U.S. national-security information was exposed through these channels. It must also establish exactly when the South Korean government discovered the intrusions, when the ministers of foreign affairs and national defense and the Office of the President were informed, and when—and precisely what—the South Korean government disclosed to the U.S. government, military, and intelligence agencies. Because this matter could pose a direct threat to U.S. national security, it cannot be entrusted solely to the scope of damage and internal investigative findings announced by the South Korean government.

A Zero-Day Does Not Explain Ten Months of Undetected Access

South Korea is widely regarded as a global information-technology powerhouse, yet repeated incidents have exposed just how seriously vulnerable the country remains when it comes to security. Because IT systems are used so extensively across the government and society, the damage caused by a breach can also spread more rapidly and on a far larger scale. Even if a zero-day vulnerability was used to gain initial entry, it does not explain how an attacker could operate inside the system for approximately ten months under valid software privileges without being detected. Moreover, because the South Korean government knew of the intrusion and still failed to disclose it immediately, responsibility must also be assigned for why the incident was concealed.

The Foreign Ministry said the attacker exploited not only a zero-day vulnerability but also inadequate security configurations. If so, what privileges did the attacker obtain after gaining entry, how were administrator accounts managed, and why were external access and account changes not detected?

If the software developer retained remote-access privileges for maintenance, the Foreign Ministry should have independently recorded and monitored connection times, user accounts, and the work performed. If administrator privileges and activity logs were managed only within the compromised system itself, the attacker could have disguised malicious activity as legitimate maintenance work and erased the evidence of access.

It must also be established whether the National Diplomatic Academy system shared accounts or authentication infrastructure with the Foreign Ministry’s email system, single sign-on service, personnel system, or overseas mission administrative network. If the same administrator accounts, passwords, or authentication tokens were used across other systems, the damage would not be limited to information stored in the education platform. Investigators must also determine whether the same products and security configurations were used in other Foreign Ministry systems or within the Ministry of National Defense, intelligence agencies, or the Office of the President.

The fact that an attacker operated for ten months inside a system used by hundreds of diplomats and intelligence officers means that the Foreign Ministry’s access controls, monitoring, and oversight of outside contractors failed. Given that the South Korean government knew about the intrusion and still withheld it from the public, it is clear that the words “zero-day vulnerability” cannot be allowed to bury the real issue.

The Foreign Ministry Confirmed the Intrusion but Kept It Secret for Five Months

The Foreign Ministry has not disclosed when it confirmed that information had been exfiltrated, when it identified the victims, or when the Office of the President was notified. The presidential office has likewise remained silent, issuing no statement while diverting public attention elsewhere.

Because the victims were not warned immediately, diplomats and intelligence officers may have continued using their existing email accounts, passwords, mobile phones, and personal messaging applications throughout that period. Even if the attacker had already begun follow-up operations using their names and account information, the victims may have failed to recognize the threat and deleted suspicious messages and access records before they could be preserved as evidence.

The Foreign Ministry’s failure to disclose the incident was serious, but the more important question is when the victims themselves received a security warning. Even before the attacker and full extent of the damage had been confirmed, officials should have been instructed to replace their accounts, preserve communications records, and report suspicious contacts. If the Foreign Ministry concealed the incident for five months without even warning the intelligence officers whose information had been exposed, this was far more serious than a mere delay in public disclosure.

It must also be determined who decided to postpone disclosure. If working-level Foreign Ministry officials delayed reporting the matter to senior officials, the reporting system failed. If the minister and the Office of the President were informed early and still chose not to disclose it, the government can only be regarded as having covered it up.

All that has been made public so far is that the system was shut down and an investigation was opened. The full timeline—from detection of the intrusion to confirmation of the damage, notification of the victims, and ultimately notification of the U.S. government—has yet to be disclosed.

When Was the United States Informed, and What Was It Told?

Did the South Korean government notify the United States before disclosing the incident to the South Korean public? Approximately 28,000 U.S. troops are stationed in South Korea, and the country plays a critical geopolitical role in deterring North Korea and countering China. Under the U.S.-ROK Mutual Defense Treaty, the United States shares sensitive national-security information with the South Korean government. The large-scale exposure of South Korean diplomats and intelligence officers therefore means that U.S. government, military, and intelligence personnel—and the security information connected to them—may also have been compromised.

The South Korean government claims that it has not yet identified the attacker. Yet it defies credulity that a government that promotes South Korea as a global IT powerhouse, seeks investment from American companies, and promises to transform the country into an artificial-intelligence power still cannot identify who controlled one of its core diplomatic systems for ten months. If the government confirmed the intrusion and then concealed it for approximately five months, there is no alternative but to question what it knew and why it hid the truth.

It remains unknown whether the State Department, Department of Defense, U.S. intelligence community, or U.S. Forces Korea was the first American institution to be notified. It is also unknown whether the South Korean government informed the United States of the suspicious activity in February, whether it disclosed that the identities of hundreds of intelligence officers had been exposed, or whether it supplied additional information as the known scope of the damage expanded.

If the South Korean government notified the United States through unofficial channels, the substance of that notification must also be examined. Merely stating that the National Diplomatic Academy system had been hacked is entirely different from providing the names, job titles, duty stations, account information, and access records of the victims. If information belonging to hundreds of intelligence officers was exposed, investigators must also examine the American institutions and political figures they contacted, the joint work they conducted, and the communications channels they used. Only then can the United States determine which officials in the State Department, Department of Defense, intelligence agencies, Congress, and the defense industry may have been exposed to follow-up attacks.

The training courses and enrollment records are also necessary. What a person was trained to do may reveal that individual’s responsibilities and future posting. If the attacker observed account creation and organizational changes over an extended period, newly selected overseas personnel may have been identified before their assignments were officially announced.

The United States must not accept the notification date claimed by the South Korean government without independent confirmation. It must compare Seoul’s account against the emails, reports, and meeting records actually received by U.S. institutions.

The Armed Forces Medical Command Officially Acknowledged Unauthorized Access to a Military Medical Information System

On May 15, 2026, the Armed Forces Medical Command posted a notice on its website titled “Notice Regarding Suspected Personal Information Exposure Related to Mobile PACS.” According to the notice, an unauthorized person accessed the mobile Picture Archiving and Communication System used by military hospitals in Yangju, Goyang, Pocheon, Gangneung, Guri, and Daegu sometime between November and December 2025. The information believed to have been exposed included names, sex, age, the dates and times medical images were taken, and CT, MRI, and X-ray images. This means that not only the identities of military personnel but also their physical conditions and treatment histories may have been exposed.

The Armed Forces Medical Command said the incident had been reported to relevant military agencies and the Korea Internet & Security Agency and that an investigation was underway. It also said the mobile PACS service had been suspended and unauthorized external communications blocked. The Cyber Operations Command and the Defense Counterintelligence Command were brought in to conduct investigative and technical analysis.

The official notice did not disclose how the unauthorized person gained access, how much information was accessed, or when the military first discovered the intrusion. South Korea has now suffered the successive exposure of personal information belonging first to diplomats and intelligence officers—people at the center of national security—and then to military personnel, including their medical and physical information. This is evidence that a coordinated penetration of South Korea’s diplomatic, intelligence, and military systems is underway.

In a follow-up report on July 23, the JoongAng Ilbo said the unauthorized individual had accessed approximately eight gigabytes of data, equivalent to roughly 1,000 X-ray, CT, and MRI images. At the time, the system held medical imaging records belonging to approximately 1.15 million people, but authorities had not determined whose records had been viewed or downloaded.

Investigators found that the intruder had used a personal computer to reach the mobile PACS through a particular communications port on the Armed Forces Medical Command website that should have been closed for security reasons. That port remained accessible from outside the network from November 2025 through March 2026.

The Armed Forces Medical Command did not discover the exposure until the Defense Counterintelligence Command conducted a central security audit in April 2026. After the Defense Counterintelligence Command and Cyber Operations Command concluded that a personal-information breach was highly likely, the Ministry of National Defense formed a joint investigation team in early June.

The Leaked List Exposes Not Only Current Personnel but Past Intelligence Networks

The exposure of the names, job titles, and duty stations of South Korean diplomats and intelligence officers is not merely the loss of personal information. It may also expose the work they performed involving North Korean sanctions, extended deterrence, export controls, defense negotiations, U.S.-ROK information sharing, and the networks of contacts they developed over time.

Account-creation records and training assignments accumulated over an extended period may include not only current personnel but also individuals scheduled for future assignments to overseas missions and key government departments. By tracing the past duty stations, meetings, and cooperative activities of exposed personnel, an attacker may be able to identify local partners and sources, as well as their contacts inside the U.S. government, military, and intelligence community.

Document authors, legal reviewers, interpreters, records officers, and outside experts may also appear in email distribution lists and follow-up records. The attacker could therefore identify not only senior officials but the working-level network that actually carries out U.S.-ROK intelligence cooperation. The United States must include current duties, past contact networks, and future assignments within the scope of its investigation.

The Identity of a Real Diplomat Becomes a Gateway for Attacking U.S. Institutions

The identities of exposed South Korean diplomats and intelligence officers can be used in impersonation attacks against the U.S. government, Congress, the military, and defense contractors.

An attacker could use the name of an actual official at the South Korean Embassy in Washington to send supposed follow-up materials from a meeting to a State Department employee, deceive a congressional staff member with documents presented as a confidential briefing package, or send the Department of Defense and defense companies what appear to be secure videoconference links or export-approval documents while requesting technical materials and contact information for responsible officials.

When an attacker uses a real name, official title, previous meeting topic, and authentic document format, the communication appears not as a new attack but as a continuation of existing work. Even a minor request to confirm a schedule or introduce the proper official can be used to elicit a reply, capture the recipient’s writing style and signature, verify an active contact address, and move closer to a more important target.

The attacker does not need to penetrate an official government network directly. By targeting personal email accounts, mobile phones, and messaging applications, the exposed identity of a South Korean diplomat becomes a path to approaching government officials and military and defense-industry personnel outside the protected boundaries of U.S. institutional networks.

In a Military Crisis, False Messages Could Disrupt the U.S.-ROK Response

During a North Korean missile launch or military clash, when the United States and South Korea must coordinate their response within a narrow window of time, false messages sent under the name of a real official and in the format of authentic government documents could disrupt the judgment and response of both countries.

An attacker could send Washington a document claiming that Seoul opposes a particular military action while simultaneously telling South Korean officials that Washington has already made its decision. If the attacker changes only the key language inside a genuine document format based on wording used in previous consultations, policy coordination and military action could be delayed while working-level officials struggle to verify what is authentic.

False documents concerning combined military exercises, North Korean sanctions, or the deployment of U.S. forces could also be circulated through the media and financial markets, producing diplomatic disorder and market volatility.

The Exposed Data Can Be Used for Long-Term Recruitment and Blackmail

Foreign intelligence services can combine the leaked personnel data with publicly available employment histories, family relationships, property records, and litigation records to identify individuals for recruitment.

Research institutes, consulting firms, universities, and international conferences can be used as cover for offers of advisory work, speaking engagements, research contracts, or employment. Such approaches may initially appear to be legitimate professional opportunities, but once a relationship has been established, they can become a channel for demanding information about internal government officials, the positions of American counterparts, confidential meetings, and other nonpublic information.

Families also become targets. A name and duty station may be enough to identify a spouse’s employer, a child’s school, the family’s residence, and its daily movements. Attackers can then impersonate an embassy, school, hospital, or airline to obtain passport information and travel schedules or to place pressure on family members.

Once a personnel list has been stolen, restoring the server and changing passwords will not make it disappear. An individual who appears unimportant today may later be promoted or transferred to the presidential office, an intelligence agency, or a major overseas mission, at which point the value of the information stolen years earlier rises again.

The United States Must Not Wait for the South Korean Government’s Final Investigation

An attacker with administrator privileges can alter user information and account-recovery addresses, create new accounts, and delete or modify access records. The records and victim lists currently held by the South Korean government therefore cannot be assumed to reveal the full extent of the damage.

The United States must obtain more than a victim count and summary of findings prepared by the South Korean government. It must secure the raw logs from the National Diplomatic Academy and military medical information systems, backups created before the attacks, records of accounts that were created, modified, or deleted, administrator privileges and authentication tokens, and connection records held by software developers and hosting providers. It must also compare the intrusion-detection and U.S.-notification dates claimed by the South Korean government against emails, reports, and meeting records held by U.S. agencies, while reopening the examination of suspicious emails, document requests, and abnormal account activity involving the names of South Korean diplomats and intelligence officers since the spring of 2025.

The National Diplomatic Academy victim list must also be compared with the contact records of the U.S. government, military, and intelligence agencies to determine whether anyone not classified by the South Korean government as a victim had access to sensitive U.S. information or operations. Investigators must also obtain the communications-port records and eight-gigabyte access records from the military medical incident, along with the Defense Counterintelligence Command’s April audit materials and the joint investigation team’s June records.

Conclusion

Lists of South Korean diplomatic and intelligence personnel and the medical information of military service members have been exposed in successive breaches, yet the South Korean government has not disclosed the full sequence of intrusion detection, internal reporting, victim notification, and notification of the United States.

If the identities and account information of hundreds of diplomats and intelligence officers were compromised, the U.S. government, military, intelligence agencies, Congress, and defense-industry personnel who had contact with them may already have been exposed to follow-up attacks.

The United States must not wait for Seoul’s internal investigation to reach its final conclusions. It must directly obtain the raw logs and notification records and immediately determine whether U.S. national-security information and human networks were compromised through these channels.


Part I of this special report is available at here:


Principal Sources

Ministry of Foreign Affairs, Republic of Korea, “Statement Regarding the Cyberattack on the Korea National Diplomatic Academy Online Education System,” July 20, 2026.

Republic of Korea Armed Forces Medical Command, “Notice Regarding Suspected Personal Information Exposure Related to Mobile PACS,” May 15, 2026.

Lee Yoo-jung, JoongAng Ilbo, “[Exclusive] Military Personnel Breached After Diplomats—Evidence of Eight-Gigabyte Leak Including Names and Diagnoses,” July 23, 2026.


- Advertisement -spot_img

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article