[SPECIAL REPORT II] Washington Can No Longer Rely on Seoul’s Explanations

Ten Months Inside the Korea National Diplomatic Academy, Five Months of Silence—and Now the Military Medical Information Network Has Been Breached

by Jean CummingsCo-Editor-in-Chief and Senior Columnist, The Korea Signal

On July 20, 2026, South Korea’s Ministry of Foreign Affairs disclosed that the online education system of the Korea National Diplomatic Academy had been hacked, resulting in the large-scale exposure of information belonging to diplomatic and national-security personnel. The attacker entered the server sometime between April and May 2025 and maintained access until February 2026, remaining inside the system for approximately ten months. The Foreign Ministry said both a zero-day vulnerability and inadequate security configurations had been exploited.

The system contained the names, user IDs, email addresses, encrypted passwords, workplaces, job titles, training materials, and course records of Foreign Ministry headquarters staff, diplomats stationed at overseas missions, officials seconded from other government ministries, locally hired diplomatic personnel, and intelligence officers posted abroad. As many as 10,000 people may have been affected, including hundreds of intelligence officers posted to overseas missions in official capacities, creating a grave national-security crisis.

The Foreign Ministry said it was notified by a related government agency of abnormal access activity in early February 2026 and then shut down the system. Yet the incident was not disclosed until July 20, approximately five months later. Former and current diplomats and government attachés whose information may have been compromised were also reportedly not informed before the public announcement.

During the same period, unauthorized access was also discovered in a South Korean military medical information system, bringing the situation to the point where classified national-security information can no longer be left to the South Korean government’s explanations and internal investigations alone. In an official notice issued on May 15, 2026, the Armed Forces Medical Command acknowledged that an outsider had accessed the mobile medical image storage and transmission system used by six military hospitals. On July 23, the JoongAng Ilbo reported that an unauthorized individual had accessed approximately eight gigabytes of data and that a communications port that should have remained closed for security reasons had been exposed to outside access for several months.

Lists of South Korean diplomatic and intelligence personnel and the medical information of military service members were exposed through separate systems. The South Korean government failed to detect these intrusions at an early stage and, even after the incidents became public, has responded by downplaying them rather than treating them with the seriousness they demand or taking aggressive action. The government has yet to identify the attacker or determine the full extent of the damage, and the fact that the Foreign Ministry confirmed the National Diplomatic Academy intrusion but kept it from the public for approximately five months provides ample reason to suspect that the government is concealing something.

The United States must immediately launch an independent investigation to determine whether U.S. national-security information was exposed through these channels. It must also establish exactly when the South Korean government discovered the intrusions, when the ministers of foreign affairs and national defense and the Office of the President were informed, and when—and precisely what—the South Korean government disclosed to the U.S. government, military, and intelligence agencies. Because this matter could pose a direct threat to U.S. national security, it cannot be entrusted solely to the scope of damage and internal investigative findings announced by the South Korean government.

A Zero-Day Does Not Explain Ten Months of Undetected Access

South Korea is widely regarded as a global information-technology powerhouse, yet repeated incidents have exposed just how seriously vulnerable the country remains when it comes to security. Because IT systems are used so extensively across the government and society, the damage caused by a breach can also spread more rapidly and on a far larger scale. Even if a zero-day vulnerability was used to gain initial entry, it does not explain how an attacker could operate inside the system for approximately ten months under valid software privileges without being detected. Moreover, because the South Korean government knew of the intrusion and still failed to disclose it immediately, responsibility must also be assigned for why the incident was concealed.

The Foreign Ministry said the attacker exploited not only a zero-day vulnerability but also inadequate security configurations. If so, what privileges did the attacker obtain after gaining entry, how were administrator accounts managed, and why were external access and account changes not detected?

You are unauthorized to view this page. Please log in to read this page in full.
이 페이지를 보실 권한이 없습니다. 이 글 전문과 한글 버전을 읽으시려면 로그인을 먼저 해주십시오.

Please renew your membership or subscribe a membership if you  didn't yet. Thank you.
멤버십을 갱신하시거나, 만약 구독하지 않으셨다면 구독을 먼저 해주시기 바랍니다. 감사합니다.

정기구독 신청하기 ← click here to subscribe. 여기를 클릭해서 구독해 주세요.

- Advertisement -spot_img

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article