Two Seoul Megachurches Probe Data Exposure After Separate Network Intrusions

Yoido Full Gospel and SaRang churches probe suspected network intrusions reported by Oasis Security over possible exposure of member and employee data.

Two Seoul Megachurches Probe Data Exposure After Separate Network Intrusions
Data Breaches

Illustrative image generated with AI

Suspected breaches surfaced weeks after the likely intrusions

Two major churches in Seoul are investigating suspected cyberattacks that may have exposed information belonging to congregants, employees and the organizations themselves.

Yoido Full Gospel Church and SaRang Church acknowledged their investigations after South Korean cybersecurity company Oasis Security published findings this week based on data recovered from an attacker-controlled server. Oasis did not identify either church in its report, although both organizations subsequently confirmed suspected incidents to local media.

The researchers assessed that the intrusions probably occurred in August. They did not provide exact incident dates. That places the suspected compromises several weeks before their public disclosure this week.

Yoido Full Gospel Church said on Wednesday that it had identified a dataset containing personal information associated with approximately 850,000 members. The church had previously reported that South Korea’s internet security agency alerted it to a suspected personal-information breach involving its systems.

SaRang Church separately confirmed that it was examining a suspected cyberattack. It has not publicly attributed the activity or provided an estimate of how many people may be affected.

Neither the institutions’ statements nor the reporting on the church investigations establishes the full scope of confirmed access.

The available figures describe different populations

The numbers disclosed so far should not be combined into a single victim total.

Yoido said the dataset it found contained personal information associated with approximately 850,000 members. That is a description of the data identified during its investigation, not necessarily a verified count of unique people whose information was accessed or extracted.

The church has historically reported membership of around 800,000 and is considered one of the world’s largest Protestant churches. The available information does not explain why the dataset figure exceeds that historical membership estimate. It could reflect differences in recordkeeping, time periods or duplicated entries, but none of those possibilities has been established.

Oasis separately described records associated with approximately 89,000 church members. The researchers also reported finding human-resources files for 286 employees, including the senior pastor, along with student and staff information connected to a college ministry.

The technical report does not specify which named church that dataset came from. It also does not establish whether the approximately 89,000 people overlap with the population represented in Yoido’s approximately 850,000-member dataset.

SaRang Church has not released an affected-person count. Its ministries serve children, students and young adults, but the available reporting does not connect any particular category of exposed records to the church.

Researchers found two different routes into the organizations

Oasis described two distinct intrusion methods but did not map either one to Yoido Full Gospel Church or SaRang Church.

In one case, the attackers installed a web shell on a compromised server. A web shell is server-side code that provides remote command or administration capabilities through a web-accessible interface. According to the researchers, the attackers used that foothold to obtain administrator-level access and move into internal systems.

Oasis reported recovering more than 47 gigabytes of data linked to this intrusion. The material allegedly included personal information, financial records, internal communications and administrative documents.

The attackers reportedly reached databases and collected membership data, payroll and accounting records, internal messages and employee login credentials. Researchers also found evidence of access to network storage holding internal reports and backups.

The second intrusion relied on a different combination of weaknesses. Oasis said the attackers used previously leaked passwords together with security flaws in internal applications to access accounts and protected information.

Some of those application vulnerabilities reportedly allowed password resets for other users. That capability could let an intruder take over additional accounts without knowing their existing passwords. The attackers then accessed the organization’s SAP environment, which contained business and employee information.

No CVE identifiers, affected software versions or patch references are provided in the material available for this account. Consequently, administrators cannot use the public description alone to determine whether a particular product update would address the reported application flaws.

Infrastructure reuse suggests a link, not common attribution

Oasis found that the attackers reused infrastructure previously associated with the compromise of an unnamed U.S.-based Christian content platform.

That overlap provides a technical connection between the incidents. It does not, by itself, prove that the same individuals carried out every compromise involving the infrastructure. Servers, domains and access credentials can be shared, transferred or reused by multiple operators.

The researchers did not identify the attackers, determine their nationality or establish a motive. There is therefore no supported basis for attributing the church intrusions to a particular government, criminal group or ideological campaign.

Oasis also reported evidence that artificial intelligence was used for vulnerability analysis, software examination, movement through internal networks and data extraction. This remains a researcher finding rather than an independently demonstrated account of the tools involved.

The available details do not identify an AI model, agent framework or service. Nor do they show which actions were autonomous, which were merely assisted by software, or whether AI materially changed the outcome of either intrusion. The claim should therefore be treated as a reported aspect of the attackers’ workflow, not proof of a fully automated operation.

Sensitive records create risks beyond the initial compromise

The reported data categories create potential consequences for both congregants and church employees. Personal details, HR files, payroll records and internal communications could support impersonation, targeted phishing or attempts to take over additional accounts.

Exposed credentials present a more immediate operational concern, particularly when people reuse passwords across church, work and personal services. Access to backups and network storage could also give an attacker a broader view of an organization’s systems and internal history.

Those are potential risks based on the types of information described. The reporting does not confirm subsequent fraud, public release of the data, financial losses or other downstream misuse.

The incidents may also affect people beyond formal church membership. Employee records and college-ministry files involve different populations, while a membership database may contain historical or administrative entries that do not correspond directly to current congregants.

Until the investigations establish what was accessed, copied and retained, dataset size should not be treated as a final victim count.

What organizations and potentially affected people can do

Yoido Full Gospel Church said it was working with authorities and cybersecurity specialists to establish the extent of the incident and prevent further damage. SaRang Church said it was investigating while taking steps intended to limit additional harm.

Neither church has publicly detailed its containment work in the cited reporting. There is no disclosed information there about credential resets, server rebuilding, SAP remediation or specific application patches.

Given the intrusion methods reported by Oasis, relevant defensive checks would include reviewing unauthorized password resets, administrator-account activity, web-server changes and unexpected access to SAP, databases, backups and network storage. Organizations should also invalidate exposed credentials and investigate whether the same passwords were used elsewhere. These are defensive priorities derived from the reported techniques, not measures the churches have confirmed completing.

People notified that their information was involved should treat unexpected messages referencing church membership, payroll, employment or ministry activities with caution. Changing reused passwords and enabling multi-factor authentication where available can reduce the risk that exposed credentials lead to another account compromise.

The reporting available for this account does not include indicators of compromise that defenders can search for directly. Further notifications from the churches or South Korean authorities will be necessary to clarify which systems and individuals were actually affected.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →