Two South Korean Megachurches Investigate Breaches Affecting Hundreds of Thousands of Members
Two of South Korea's largest Protestant churches, Yoido Full Gospel Church and SaRang Church, are investigating suspected cyberattacks that may have exposed sensitive information about hundreds of thousands of members. Yoido Full Gospel Church said it identified one dataset containing personal information linked to about 850,000 members. SaRang Church confirmed its investigation but has not said how many people may be affected or who the attackers are.
The incidents came to light after South Korean security firm Oasis Security analysed files recovered from an attacker-controlled server overseas. In one case, researchers found more than 47 gigabytes of data, including personal information, financial records, internal communications and administrative documents. The attackers installed a web shell, which is malicious software that lets hackers remotely control a compromised server, and used it to gain administrator-level access. They then reached databases, payroll and accounting records, internal messages, employee login credentials, and a network storage system holding reports and backups.
The second intrusion used a different method. Attackers relied on previously leaked passwords and security flaws in internal applications to reach accounts and information they were not authorised to see. Some of the flaws also let them reset other users' passwords. Yoido Full Gospel Church said it is working with authorities and cybersecurity specialists to determine the extent of the incident and prevent further damage.