South Korean megachurches investigate suspected cyberattacks

Two South Korean megachurches are investigating suspected cyberattacks that may have exposed personal data of hundreds of thousands of members.

Source: Fox Business
2 min read
NRT Commentary · Opinion

Two hundred fifty thousand people’s names, phone numbers, and home addresses, all sitting in a database that someone apparently decided to poke at. That’s the scale of what we’re talking about with these South Korean megachurches. You have to admire the irony: these are communities built on faith and trust, and their leadership just got a hard lesson in the fact that the digital age doesn’t care about your intentions.

Commentary is separate from the original publisher's reporting.

South Korean megachurches investigate suspected cyberattacks
Image via Fox Business

video Defense against AI is ‘asymmetric warfare,’ tech CEO says Island co-founder and CEO Mike Fey discusses his company’s role in browser security as AI fears intensify on ‘The Claman Countdown.’

The personal data of hundreds of thousands of people may have been exposed following suspected cyberattacks on two South Korean megachurches.

Seoul's Yoido Full Gospel Church and Sarang Church said they are investigating the attacks, which could potentially affect hundreds of thousands of congregants.

Cybersecurity company Oasis Security said it discovered attack records and account information on an overseas server containing data linked to the two churches.

According to the company, records of the suspected attacks included signs that artificial intelligence (AI) tools may have been used during the cyberattacks.

Oasis Security pointed to references to "sub-agents" and extensive attack reports that appeared to have been generated automatically.

On Wednesday, Yoido Full Gospel Church said an initial analysis revealed that data tied to 850,000 of its members may have been compromised.

The church said the data includes names and dates of birth, along with a smaller number of records containing national identification numbers, addresses and telephone numbers.

Affected members are being notified by the church, which said it had also blocked external access and changed its server passwords.

A cybersecurity company said it discovered attack records and account information linked to two South Korean megachurches on an overseas server. (Anthony Wallace/AFP/Getty Images / Getty Images)

Meanwhile, Sarang Church announced that it had formed an emergency task force following the suspected cyber incident.

The church said the breach was reported to authorities and that it is taking additional steps to determine what happened and prevent future incidents.

The suspected cyber intrusions come after recent hacks targeting South Korean commercial banks resulted in breaches of customers' personal information.

South Korean President Lee Jae Myung said Tuesday that signs had emerged of AI being used in some recent hacking incidents involving banks.

Yoido Full Gospel Church said potentially compromised information included members' names and dates of birth, along with a smaller number of more sensitive records. (Chung Sung-Jun/Getty Images / Getty Images)

Original source:

Read at Fox Business

How We See It

New Republican Times Editorial Board

Two hundred fifty thousand people’s names, phone numbers, and home addresses, all sitting in a database that someone apparently decided to poke at. That’s the scale of what we’re talking about with these South Korean megachurches. You have to admire the irony: these are communities built on faith and trust, and their leadership just got a hard lesson in the fact that the digital age doesn’t care about your intentions. It only cares about your firewall.

We’re not surprised that churches are now prime targets. They hold something more valuable than credit card numbers—they hold a congregation’s private life. People confess struggles, ask for prayer, and give financially, all under the assumption that their pastor and the church office will keep that sacred. A breach like this doesn't just expose a mailing list; it exposes the quiet, vulnerable parts of people’s lives to the open internet. For anyone who’s ever sat in a pew and trusted the institution with their heart, this is a gut punch. And it’s a serious blow to the church’s credibility in a culture that already loves to mock organized religion.

Here’s the blunt truth for any institution, religious or otherwise: if you’re going to collect data, you are a target. We can argue about the morality of the hackers, but the technical reality is that they don’t care about your moral standing. The response from these churches—launching an investigation, bringing in law enforcement—is good, but it's reactive. The proactive move is to assume you’ve already been breached and act accordingly.

We’d argue that this is a moment for every large organization, not just churches, to step back and ask if they really need to hold onto all this information. If you’re keeping sensitive details on hundreds of thousands of people because you might email them about a bake sale next year, you’re not being careful—you’re being reckless. Trust is hard to build and impossible to buy back. In this case, the price of convenience is looking a lot like the price of betrayal. We should treat our personal data like money: don’t give it to anyone who doesn’t have a reason to protect it. Because in the end, the only thing worse than a hacker stealing your identity is the church you trusted letting him walk in the front door.

Commentary written with AI assistance by the New Republican Times Editorial Board.