
Hackers broke into the digital records of two of South Korea’s biggest churches, putting the personal data of hundreds of thousands of worshippers at risk.
Story Snapshot
- Yoido Full Gospel Church says a review found that data on 850,000 members may have leaked, including names and birthdates.
- Sarang Church data turned up on a hacker’s server, including about 89,000 member records and info on 286 staff.
- Security firm Oasis Security says attackers used a web shell to break into a church computer system and grab administrator access.
- Reported numbers swing wildly across outlets, from 89,000 records to nearly 960,000, showing how fast and messy early breach reporting can get.
Two Of Korea’s Biggest Congregations Targeted
Yoido Full Gospel Church in Seoul calls itself the world’s largest Protestant congregation by registered membership. On October 7, it said its internal review found that names, birthdates, and other personal details tied to 850,000 members may have been exposed. The church also said some of the exposed data came from modification history records, logs that track changes made to member files over time.
Sarang Church in Seoul’s Seocho District faces a separate but related problem. Investigators reportedly found data linked to the church sitting on an external attacker’s server. That stash included personal details on roughly 89,000 members, names, addresses, phone numbers, plus records for 286 staff and officials, including the senior pastor.
How The Breach Was Found And What It Looked Like
Security firm Oasis Security says it recovered attack tools and logs from an overseas attacker’s server last month. The firm found large volumes of data tied to both churches on that server. According to the firm, the attacker used a web shell, a small hidden program planted on a server, to break into church computer systems and gain database administrator access.
That level of access matters because a database administrator can typically view, copy, or alter almost anything stored in a system. That kind of control is no minor glitch. It is the digital equivalent of stealing a master key to a filing room packed with tithing records, family details, and contact information for an entire congregation.
Why The Numbers Keep Changing
Reports on the scope of the breach have varied a lot. Some outlets cited around 89,000 records tied to Sarang Church. Others reported up to 850,000 affected members at Yoido Full Gospel Church. Still others cited numbers near 960,000 when combining both churches’ data. The gap likely reflects confusion between unique people, update logs, and combined datasets rather than one clean, confirmed count.
#southkorea#MegaChurches#probe#Suspected#ailinked#CyberAttack
SEOUL, Oct 7 – Two South Korean megachurches are investigating suspected cyberattacks that may have exposed the personal data of hundreds of thousands of congregants, with evidence suggesting AI tools may pic.twitter.com/4OCOZENkeb— Raashid Saeed (@raashidsaeed3) October 7, 2026
This kind of early-stage confusion is common in major data breaches. Companies and institutions usually learn about intrusions through outside security researchers piecing together clues from attacker infrastructure, not through a complete internal audit on day one. That pattern fits here, with Oasis Security’s server findings driving most of the public reporting so far.
What Makes Church Data Especially Sensitive
Membership and donation records at Korean churches often include deeply personal details: family relationships, giving histories, and identification numbers used for official purposes. One Korean industry report noted that church-held information goes far beyond simple contact lists, touching faith life, finances, and family ties. That raises the stakes for members whose data may now sit in the wrong hands.
Both churches say they are conducting internal reviews and have taken steps like password resets following the discovery. Neither institution has published a full technical timeline detailing exactly when the intrusion began or how containment efforts unfolded. Members and outside observers will be watching for a more complete accounting as the investigations continue.
Sources:
asiae.co.kr, en.sedaily.com, news.sbs.co.kr














