Culture & Life Yonhap News Culture · 4h ago

Over 1 Million Churchgoers' Data at Risk as Hackers Breach Top South Korean Mega-Churches

Key Points
  • Hackers infiltrated the internal ERP and groupware systems of Seoul's Yoido Full Gospel Church and SaRang Church, exposing confidential churchgoer records, staff details, and donation histories.
  • The breach has caused major concern across South Korea as approximately one million member profiles and decades of sensitive financial and tithing records were reportedly transferred to overseas serve
  • South Korean mega-churches operate massive digital infrastructures akin to large enterprises, and investigators revealed the attack utilized infrastructure linked to a compromised U.S. religious media
Summary South Korea is reeling from a massive cybersecurity breach targeting two of the country's most prominent mega-churches, exposing sensitive personal data and financial records belonging to an estimated one million congregation members. According to cybersecurity intelligence firm Oasis Security, hackers breached internal systems at Yoido Full Gospel Church and SaRang Church, both located in Seoul, potentially exfiltrating vast databases of confidential information to overseas servers. In South Korea, mega-churches are far more than places of worship; they are massive institutional ecosystems with tens or hundreds of thousands of registered congregants, operating sophisticated digital infrastructures that rival major corporations. Yoido Full Gospel Church, globally recognized as one of the largest Protestant congregations in the world, suffered an infiltration into its Enterprise Resource Planning (ERP) servers via a malicious web shell script. The attackers gained database administrator privileges, compromising approximately 960,000 member profiles updated over the past two years, 330,000 donation and tithing records, 68,000 electronic approval documents, and nearly 15,000 internal messenger chat logs—totaling around 47.3 GB of data. Meanwhile, SaRang Church in the affluent Seocho district was breached using compromised credentials to enter its groupware server. The intruder exploited vulnerabilities to escalate administrative privileges and utilized Single Sign-On (SSO) architecture to move laterally into the church's ERP systems. This attack allegedly exposed data on 89,000 churchgoers alongside private records and photos of nearly 300 staff members. Investigators uncovered alarming cross-border connections during forensic analysis. Credentials from a compromised administrator account tied to a U.S. religious content and streaming platform were allegedly repurposed to store and transfer the Korean church data on foreign servers. While experts caution that using the same infrastructure does not definitively prove the attackers are identical, it underscores a sophisticated, coordinated campaign exploiting digital vulnerabilities within religious networks. Both churches have confirmed that they are cooperating with the Korea Internet & Security Agency (KISA) and specialized cybersecurity teams to assess the full scope of the breach and overhaul their network security. The incident has ignited widespread debate across Korea regarding the cybersecurity posture of large religious and nonprofit institutions, highlighting the urgent need to secure interconnected databases and authentication protocols that safeguard millions of citizens' most private personal and financial details.
Sponsored · Ad