Cyberhackers target two South Korean megachurches, potentially revealing congregants' data
Suspected cyberattacks on two major Korean megachurches, including what is believed to be the world's largest church congregation, may have exposed the personal data of hundreds of thousands of members.
The breach raises serious concerns about the security of sensitive information that faithful churchgoers trust their congregations with, according to Faith Freedom Report on Oct. 10 following a disclosure by Oasis Security.
https://www.faithfreedomreport.com/south-korean-megachurch-cyberattack-threatens-hundreds-of-thousands-of-members/
The prognosis follows a report by The Record that two of South Korea's largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of members, including personal details, financial records and internal documents
Oasis said on its Website: "Oasis Security analyzed files from an attacker server used against two of South Korea's largest churches, [Victim A] and [Victim B]. A web shell on [Victim A]'s ERP led to sysadmin access and the collection of member, financial, and administrative data. [Victim B] was compromised using previously leaked credentials and IDOR vulnerabilities affecting its groupware and SIMS systems, followed by access to SAP and the identification of assets associated with its college ministry, GitHub, and Firebase."
The Record is a well-known cybersecurity journalism publication that frequently covers major digital security incidents, state-sponsored hacks, and data breaches in South Korea and elsewhere.
- 850,000 CHURCH MEMBERS
Yoido Full Gospel Church released a statement on Oct. 7 saying it had identified one dataset containing personal information associated with approximately 850,000 members.
The church said it had been notified by South Korea's internet security agency of a suspected breach of personal information involving its systems.
It is working with authorities and cybersecurity specialists to determine the incident's scope and prevent further damage.
The Record said that SaRang Church also told local media that it was investigating a suspected cyberattack.
It was also taking steps to prevent additional damage. It has not disclosed how many people may have been affected or identified the attackers.
The cyber attacks were discovered after Oasis Security researchers analyzed files recovered from an attacker-controlled server located overseas.
The researchers did not publicly identify the two churches in their report but described separate intrusions involving large South Korean religious organizations.
In one case, researchers recovered more than 47 gigabytes of data, including personal information, financial records, internal communications and administrative documents.
The attackers installed malicious software that allows hackers to remotely control a compromised server — and used it to gain administrator-level access to the organization's internal systems.
From there, they accessed databases and other parts of the network, collecting church membership information, payroll and accounting records, internal messages and employee login credentials.
Citing Oasis Security, The Record said the compromised records included personal information associated with approximately 89,000 church members and human resources files for 286 employees, including the senior pastor.
The attackers also accessed information connected to a college ministry, including student and staff records.
The researchers said the intrusions likely occurred in August, weeks before the incidents became public, but did not identify the hackers.
Both churches are among South Korea's most prominent Protestant congregations.
Yoido Full Gospel Church has historically reported a membership of around 800,000/
That makes it one of the world's largest Protestant church congregations. SaRang Church operates a large worship complex in Seoul and runs numerous ministries serving children, students and young adults.