Cyberattack on Korean megachurches may have exposed 850K members

Christmas services are conducted from the Yoido Full Gospel Church on Dec. 25, 2023 in Seoul, South Korea. Christmas has become increasingly popular over the years in South Korea, which is the only East Asian country to recognize Christmas as a national holiday.
Christmas services are conducted from the Yoido Full Gospel Church on Dec. 25, 2023 in Seoul, South Korea. Christmas has become increasingly popular over the years in South Korea, which is the only East Asian country to recognize Christmas as a national holiday. | Chung Sung-Jun/Getty Images

Suspected cyberattacks on two Korean megachurches, including what is believed to be the world's largest church, may have exposed the personal data of hundreds of thousands of people on their membership rolls, an analysis suggests. 

The firm Oasis Security announced this week that it found attack records and account information related to Seoul's Yoido Full Gospel Church and SaRang Church on an overseas server.

The initial ‌analysis indicated data connected to 850,000 members of Yoido Full Gospel Church could be compromised, Reuters reports. 

In a statement Wednesday, Yoido Full Gospel Church said it was told about the breach by the Korea Internet & Security Agency on Tuesday afternoon. The data includes members’ names and birth dates. Some records also contain phone numbers, addresses and national identification numbers. Those additional details were in a log of edits to membership entries.

Senior Pastor Lee Young-hoon said he felt a "deep sense of responsibility for causing concern among our members as a result of this incident, and I sincerely apologize."

"As soon as we became aware of the circumstances surrounding the incident, the church worked with the relevant authorities and cybersecurity specialists to identify the method of intrusion and the extent of the damage, while taking measures to prevent any further harm," Lee said in a statement, according to The Korea Times. 

Records from the cyberattacks suggest the hackers used AI tools. Oasis noted the existance of "sub-agents" and automated attack reports. Sub-agents are helper programs that an AI model launches to handle separate parts of a task. AI’s role in the church attacks remains unclear.

“The file contained 2,629 changes to resident registration numbers, 3,964 changes to phone numbers and 7,202 changes to addresses,” Yoido said in a written statement.

Since the breach, the church has blocked outside access to its systems, changed its server passwords and begun notifying the people who may be affected.

Yoido plans to install a new firewall, a filter that keeps unwanted traffic out of a network, and to hire security firms to look for other weak points while the notices go out.

Another Seoul megachurch, SaRang Church, is dealing with a suspected attack of its own. The SaRang breach reportedly involves the files of about 89,000 congregants and 286 staff members, including the senior pastor.

Attack logs suggest the SaRang data was taken in August. The church has formed an emergency response team and reported the breach to authorities. It said it is taking further steps to find out what happened and prevent it from happening again.

Both churches said they are investigating. Neither has determined how the attackers got into its systems.

Yoido is a Pentecostal congregation affiliated with the Assemblies of God. Pastor David Yonggi Cho founded it in 1958. The church takes its name from Yeouido, an island in Seoul’s Han River where its main sanctuary stands. The Assemblies of God considers Yoido to be the world’s largest congregation.

SaRang Church is a Presbyterian congregation in southern Seoul. Pastor Ok Han-hum founded it in 1978.

South Korea assigns each resident a 13-digit resident registration number; the first six digits are the holder’s birth date. Banks, phone carriers and government offices use the number to verify a person’s identity, and South Korean law limits when organizations may collect it.

Under South Korea’s Personal Information Protection Act, organizations must notify people when their personal data has been leaked.

In September, Oasis Security found the data on a server outside South Korea while tracing internet addresses linked to suspected attacks. The server also held attack records and account details connected to both churches.

The suspected church breaches follow recent hacks of South Korean commercial banks that exposed customers’ personal information. President Lee Jae Myung said Tuesday that some of those incidents showed signs of AI use.

Shinhan Bank is one of the lenders where South Korean authorities are investigating a suspected AI-assisted hack. Local news reports said that the breach exposed the names, phone numbers, annual incomes and loan limits of about 25,000 customers. The country’s financial regulator has launched an emergency on-site inspection.

Was this article helpful?

Become a CP Insider.
Help keep The Christian Post free for everyone.

The truth has a cost, and Insiders help carry it.
A dollar from an Insider comes with no strings attached. It keeps our reporters on the story, keeps our journalism open to everyone, and keeps every editorial decision in the newsroom, where it belongs.

Become a CP Insider and choose the amount you want to pay. You can change, pause or cancel anytime. As a thank-you, you’ll get:

  • The Insider Newsletter, a members-only monthly letter from our newsroom

  • Ad-free reading across christianpost.com


From as low as $8.25/month
Prefer to give once?

We’re sorry to hear that.

Hope you’ll give us another try and check out some other articles.
Return to homepage.

Most Popular

More Articles