Concerns Grow Over National Office of Investigation Probe Into 10,000-Case Diplomatic Network Hack Amid Cover-Up Allegations and Reluctance to Report
- Input
- 2026-07-30 11:02:10
- Updated
- 2026-07-30 11:02:10

According to the judiciary and political circles on the 30th, the National Office of Investigation's Cyber Terror Investigation Unit has begun looking into the hacking of the online education system server at the Korea National Diplomatic Academy (KNDA). The compromised server stored names, email addresses, and encrypted passwords of up to 10,000 people, including current and former diplomats, officials stationed at overseas missions, and white agents from intelligence agencies. Hackers had accessed the system freely for as long as 10 months, yet MOFA was reportedly unaware of it.
The biggest hurdle to expanding the National Office of Investigation's probe is whether it can carry out a compulsory investigation into allegations of missing reports and a cover-up within MOFA. Although MOFA learned of the hack in early February after being notified by a related agency, it was found not to have reported it immediately to the control tower, including the Presidential National Security Office, for several months.
It also filed a delayed report with the Personal Information Protection Commission (PIPC), a legal obligation, only on the 19th, five months later. There are also structural limits that make it difficult for the National Office of Investigation to broaden the probe into these cover-up allegations. MOFA has strongly resisted disclosing the details of the hack or the damage caused, saying the case involves a high-level national security matter. Without internal cooperation, it is difficult to determine whether officials intentionally concealed the incident or simply made an administrative mistake. Another key issue is whether the Presidential National Security Office will be questioned as a witness. In that sense, compulsory measures are not easy, unlike in the Coupang case.
During the Coupang case, investigators were able to quickly move forward by executing strong compulsory measures, including search and seizure, in accordance with domestic laws and due process. By contrast, in this diplomatic network hack, the suspect has not been identified, and even executing warrants such as searches of MOFA headquarters or KNDA would not necessarily lead to the arrest of the actual culprit. In addition, nearly six months have already passed since the hack was discovered because MOFA's report was delayed.
Security authorities currently believe the attack, which exploited a zero-day vulnerability, may have been carried out by hacking groups linked to North Korea or China. However, identifying hackers backed by a foreign government through digital forensics alone is difficult from a legal standpoint.
The need for a joint investigation with the National Intelligence Service (NIS) and other agencies is being raised. A political source said, "Cooperation with security agencies and MOFA's willingness to provide security-related materials will determine the success or failure of the investigation."

[email protected] Kim Kyung-soo Reporter