Foxbusiness Cyberattacks on South Korean Megachurches Expose Data of Over 1 Million Members
Article Content
- •Over 1 million records from two South Korean megachurches were compromised in cyberattacks.
- •AI tools were reportedly used in the attack, indicating a sophisticated approach.
- •Both churches are investigating the breaches and have implemented security measures.
Two major South Korean churches, Yoido Full Gospel and SaRang Community Church, were targeted in cyberattacks that compromised sensitive data of approximately 1.05 million members. The attacks were confirmed by Oasis Security, which found evidence of AI tools being used during the breaches. Yoido Full Gospel Church reported that around 960,000 member records were leaked, including names, addresses, and offering histories, while SaRang Church had data of about 89,000 congregants exposed. The attackers exploited vulnerabilities in the churches' ERP systems and groupware servers, using web shells and compromised credentials. Both churches are currently investigating the incidents and have taken steps to secure their systems. The attacks have raised concerns about the increasing use of AI in cybercrime.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Sarang Church in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How many members are affected?
What data was leaked?
What actions are the churches taking?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…