South Korean megachurches probe breaches of member data
Two of South Korea's biggest Protestant churches are investigating suspected cyberattacks that may have exposed data on hundreds of thousands of congregants, along with financial records and internal documents.
Yoido Full Gospel Church and SaRang Church, both based in Seoul, acknowledged the incidents after South Korean cybersecurity firm Oasis Security published research this week. The research was based on data the firm recovered from a server controlled by the attackers.
What the churches have confirmed
On Wednesday, Yoido Full Gospel Church told local media it had identified one dataset holding personal information linked to roughly 850,000 members.
The church had earlier said that South Korea's internet security agency had notified it of a suspected breach involving its systems. It is now working with authorities and outside cybersecurity specialists to establish how far the incident reaches and to limit further damage.
SaRang Church also confirmed to local media that it is investigating a suspected cyberattack and taking steps to prevent additional harm. It has not said how many people may be affected, and it has not named the attackers.
Both congregations are among the most prominent in the country. Yoido Full Gospel Church has historically reported around 800,000 members, which places it among the largest Protestant churches in the world. SaRang Church runs a large worship complex in Seoul and operates many ministries for children, students and young adults.
Two intrusions, two methods
Oasis Security did not name the churches in its report. Instead, it described separate intrusions at large South Korean religious organizations, based on files found on an attacker-controlled server located overseas.
In the first case, researchers recovered more than 47 GB of data. It included personal information, financial records, internal communications and administrative documents.
The attackers planted a web shell, a piece of malicious software that lets an intruder control a compromised server remotely. They used it to obtain administrator-level access to the organization's internal systems.
With that access, they moved into databases and other parts of the network. They collected membership records, payroll and accounting files, internal messages and employee login credentials. Researchers also found signs that the attackers reached a network storage system holding internal reports and backups.
The second intrusion followed a different path. Here, the attackers relied on passwords that had leaked previously and on security flaws in internal applications. These weaknesses let them get into accounts and view information they were not authorized to see. Some of the flaws also allowed them to reset other users' passwords.
The attackers then reached the organization's SAP software, which it uses to run business operations and manage employee information.
According to Oasis Security, the compromised data in this case included personal information on about 89,000 church members and human resources files on 286 employees, among them the senior pastor. The attackers also accessed records tied to a college ministry, covering students and staff.
Timeline, links and AI use
The researchers believe both intrusions likely took place in August, several weeks before they became public.
Their analysis showed that the attackers reused infrastructure connected to an earlier compromise of an unnamed Christian content platform based in the U.S. This points to a technical link between the incidents.
Oasis Security did not identify the hackers. It also did not determine their nationality or why they targeted religious organizations.
The firm did report evidence that the attackers used artificial intelligence at several stages. This included analyzing vulnerabilities, examining software, moving through internal networks and extracting data.
Our Take
Churches rarely appear on lists of high-value targets, but these cases show why they should. Large congregations hold the same kinds of data as mid-sized companies: identity details, payroll, accounting records, HR files and credentials. They often do so without the security budgets or staff that a business of similar size would have.
The two attack paths are familiar. A web shell on an exposed server and reused leaked passwords are among the most common ways into a network, and both are well understood. Organizations running public-facing web applications should check for unexpected files on servers, as web shells and backdoors planted through known flaws remain a steady problem. Credential hygiene and patching of internal applications would have raised the bar in the second case.
The reported use of AI fits a wider pattern. South Korea has already seen bank breaches probed amid AI attack suspicions, and researchers have documented AI agents launching SQL injection attempts against government sites. This suggests AI tools are lowering the effort needed to find flaws and move through networks.
It is worth watching whether more religious or faith-based organizations come forward, given the infrastructure overlap with the U.S. platform, and whether the attackers' identity and motive become clearer.
