Video
[Anchor]
It has been revealed that the online education system of the Korea National Diplomatic Academy, under the Ministry of Foreign Affairs, was compromised by hackers for 10 months. The system contained the personal information of approximately 10,000 public officials, including current and former diplomats, as well as police and intelligence officers stationed at overseas diplomatic missions.
Reporter Kim Ayeong has the story.
[Reporter]
The hacked site is the online education system of the Korea National Diplomatic Academy, which operates under the Ministry of Foreign Affairs.
The system was established in 2022 during the COVID-19 pandemic to provide non-face-to-face training for diplomats and other personnel. Investigators found that hackers infiltrated the server in April and May of last year.
The investigation revealed that the hackers accessed the system intermittently until this past February.
The server contained up to 10,000 records of personal information, including that of South Korean diplomats, staff at the Foreign Ministry headquarters and overseas missions, and personnel dispatched from other government agencies.
The leaked data includes names, user IDs, encrypted passwords, and email addresses. It is also known that it is possible to infer the positions and workplaces of the individuals from this information.
[Park Il / Spokesperson for the Ministry of Foreign Affairs: We are taking this matter very seriously and will work with relevant agencies to conduct a thorough investigation into the incident.]
It is presumed that the hackers exploited an undisclosed security vulnerability that even the software manufacturer was unaware of. The Ministry of Foreign Affairs stated that it is not ruling out any possibilities, including the involvement of state-sponsored hacking organizations.
[Jo Jeong-dae / Cybersecurity Expert: If they used an unknown attack method, it is limited to what individuals can do; it is possible that North Korea or China could be behind it.]
The Ministry of Foreign Affairs stated that the National Intelligence Service notified them of the hacking in February, and they blocked access to the site immediately afterward.
(Video by Joo Yong-jin, Video Editing by Lee Seung-yeol)
---
[Anchor]
Reporter Kim Ayeong, who covers the Ministry of Foreign Affairs, is here with us.
Q. Data of up to 10,000 people compromised... What is the extent of the damage?
[Reporter Kim Ayeong: Overseas diplomatic missions are staffed not only by diplomats but also by intelligence agents, police, and military personnel. In fact, some of these assignments are classified, so their full rosters have never been made public. There is growing concern that a state-sponsored hacking group could use the 10,000 pieces of personal information stolen from the server to threaten national security. The government has explained that sensitive information such as resident registration numbers or passport numbers was not included, and that the system is separated from the internal networks of the Foreign Ministry and other agencies. However, the possibility that the hackers decrypted the encrypted passwords cannot be completely ruled out. In particular, there is a risk that the names, passwords, and email addresses could be used to facilitate secondary data theft. The Foreign Ministry only posted a notice about the hacking on its website yesterday. It has been revealed that the process of individually notifying those whose data may have been leaked has not even begun. While the Foreign Ministry claims they were cautious due to the nature of the security issue, some are criticizing the response as complacent.]
Q. Possibility of state sponsorship... Is this the work of North Korea?
[Reporter Kim Ayeong: While the Foreign Ministry added the caveat that there is insufficient technical analysis to definitively identify the perpetrators, they did mention the possibility of a state-sponsored hacking organization. The atmosphere suggests that the possibility of North Korean involvement is also being kept open. Do you remember the major hacking incident involving the court computer network two years ago? A government investigation revealed that a group presumed to be the North Korean hacking organization Lazarus had siphoned off 1,000 gigabytes of data over more than two years. Coincidentally, the Reconnaissance General Bureau, which oversees North Korean hacker groups, has recently signaled that it would engage in more aggressive activities. Some are pointing to the precedent set last year in the United States, where employees of a Chinese information technology company were indicted for hacking into the email accounts of foreign ministries in several countries, including South Korea, and are arguing that China could be behind this. Depending on the results of the government's further investigation, this could lead to diplomatic repercussions.]