South Korea says Foreign Ministry hack remains under investigation

· UPI

July 22 (Asia Today) -- South Korea has not determined who was responsible for a cyberattack on a Foreign Ministry training system and is investigating several possibilities, the country's national security adviser said Wednesday.

Wi Sung-lac, director of the presidential National Security Office, also rejected allegations that the government attempted to conceal or minimize the breach.

"There was no intention to hide anything or deceive the public," Wi told reporters at the presidential office.

He said the government delayed publicly disclosing the incident because officials first needed to address information that posed urgent national security concerns.

"After becoming aware of the incident, we consulted with the relevant departments and agencies," Wi said. "Some of the compromised information required an urgent response from a national security perspective, and it took several months to take action before making a public announcement."

He said the government had to prioritize those security measures before disclosing the breach.

"We delayed the public announcement and concentrated on responding to the security concerns, which took several months," Wi said. "We are now focusing on follow-up measures."

Wi said investigators had not clearly identified the attacker.

"We have not yet determined the identity of the hacking group and are continuing to investigate," he said. "It is difficult to reach a definitive conclusion."

Wi said authorities could make certain assessments but were keeping several possibilities open.

He also noted that diplomatic and security organizations are frequent targets of cyberattacks because of the sensitive information they handle.

"Attackers generally have a purpose when selecting a target," Wi said. "Diplomatic, security and intelligence organizations may be among those targets, and diplomatic institutions are often attacked."

Wi pledged to strengthen the government's cybersecurity systems to prevent a recurrence.

"We will use this incident as a lesson, review our security systems and make every effort to ensure that it does not happen again," he said.

The government will also develop clearer cybersecurity guidelines and strengthen its response procedures, Wi added.

The online education system operated by the Korea National Diplomatic Academy was reportedly exposed to unauthorized access for about 10 months.

The breach raised concerns that personal information belonging to thousands of current and former Foreign Ministry officials, as well as government officials stationed at overseas diplomatic missions, may have been compromised.

The attacker reportedly penetrated the academy's online education server around April or May 2025 and accessed it repeatedly until early February.

The Foreign Ministry said it learned of suspicious access in February after being notified by another government agency. It then blocked access to the system and began an investigation.

-- Reported by Asia Today; translated by UPI

© Asia Today. Unauthorized reproduction or redistribution prohibited.

Original Korean report: https://www.asiatoday.co.kr/kn/view.php?key=20260722010008159

Read More