South Korean megachurches investigate data breach of 850,000 members
The personal data of hundreds of thousands of church members may have been compromised following suspected cyberattacks on two South Korean megachurches. Seoul’s Yoido Full Gospel Church and Sarang Church confirmed they are investigating the intrusions, which cybersecurity company Oasis Security said involved overseas servers and potential artificial intelligence automation.
Data Exposure at Yoido Full Gospel Church
Yoido Full Gospel Church stated on Wednesday that an initial analysis revealed data tied to 850,000 of its members may have been breached. The exposed records include names and dates of birth, alongside a smaller number of entries containing national identification numbers, addresses, and telephone numbers.
The church initiated member notifications following the discovery. Administrators blocked external access, changed server passwords, and reported the breach to regulatory authorities.
Emergency Response and Investigation at Sarang Church
Sarang Church announced the formation of an emergency task force to manage the suspected cyber incident. Church officials confirmed that the breach was reported to authorities and that investigations are underway to determine the scope of the compromise and prevent future intrusions.
Cybersecurity firm Oasis Security reported locating attack records and account information linked to the two churches on an overseas server. The firm noted that the attack logs displayed signs of artificial intelligence utilization, pointing specifically to references of “sub-agents” and automatically generated attack reports.
Context of Recent South Korean Cyber Incidents
The megachurch cyber intrusions follow recent hacks targeting South Korean commercial banks, which resulted in leaks of customer personal information. South Korean President Lee Jae Myung stated on Tuesday that indications had emerged regarding the use of AI in some of those recent banking cyberattacks.
Authorities have not yet released definitive findings regarding the identity of the threat actors behind the church attacks.