Seoul's Yoido Full Gospel Church and Sarang Church are investigating suspected cyberattacks that may have exposed the personal data of hundreds of thousands of congregants, including 850,000 members of Yoido Full Gospel Church. Cybersecurity firm Oasis Security discovered the stolen data on an overseas server alongside logs indicating the attackers used artificial intelligence tools. The incident follows a wave of AI-assisted hacks targeting South Korean financial institutions, prompting President Lee Jae Myung to warn of a new cybersecurity crisis and triggering a 24-hour emergency response from national authorities.
Details of the compromised church data
- ▪Cybersecurity firm Oasis Security discovered approximately 89,000 cases of congregant information and 286 cases of employee information, including the senior pastor, suspected to be related to Sarang Church on an overseas attacker server.
- ▪An initial analysis by Yoido Full Gospel Church revealed that personal data tied to approximately 850,000 members, including names, dates of birth, and some national identification numbers, addresses, and telephone numbers, may have been compromised.
- ▪Oasis Security identified approximately 47.3GB of data related to Yoido Full Gospel Church on an overseas attacker server, including 330,000 offering records, 960,000 updated congregant records, 68,000 electronic approval documents, and 14,706 internal messenger conversation records.
Oasis Security findings
- ▪Oasis Security stated that there were signs the attack scope at both churches had expanded to other internal systems through externally accessed systems.
- ▪Oasis Security discovered attack records and account information on an overseas server linked to Yoido Full Gospel Church and Sarang Church, with signs of AI use including references to "sub-agents" and automatically generated attack reports.
Technical methods used in the church breaches
- ▪The attacker of Yoido Full Gospel Church reportedly infiltrated the enterprise resource planning system server using a web shell to gain database administrative privileges and access other internal systems.
- ▪Oasis Security analyzed that the administrator account of an external storage server linked to a breached U.S. religious content and streaming service was used to store and transmit data related to the South Korean churches.
Responses by the targeted churches
- ▪Sarang Church formed an emergency task force, reported the suspected cyber incident to relevant authorities, and initiated steps to determine what happened and prevent future incidents.
- ▪Yoido Full Gospel Church blocked external access, changed its server passwords, and planned to replace its firewall and work with security companies to identify system vulnerabilities.
Cyberattacks targeting South Korean financial institutions
- ▪Hacks targeting South Korean financial institutions exposed user data at seven firms, including details of approximately 25,000 Shinhan Bank customers, 40,000 Yegaram Savings Bank customers, and 2,200 Welcome Savings Bank corporate clients.
- ▪Moon Jong-hyun, head of Genians Security Center, stated on October 2, 2026, that evidence suggested Artex, a Chinese-language, open-source AI tool, was used to find and test computer system vulnerabilities in the bank attacks.
- ▪South Korean President Lee Jae Myung stated on October 6, 2026, that signs of artificial intelligence models being used had emerged in recent cyberattacks targeting South Korean financial firms.
Government response to financial sector attacks
- ▪The South Korean science ministry and its cybersecurity agency mounted a 24-hour emergency response and requested cloud providers to block activity from suspect overseas IP addresses.
- ▪Financial Services Commission chair Lee Eog-weon called for the highest level of vigilance and urged the financial sector to build systems that defend against AI attacks with AI.
Debatable claims
- ▪Megachurches should be subject to the same cybersecurity regulations as commercial enterprises
- ▪Megachurches' extensive digital record-keeping of congregant activities is justified by administrative needs
- ▪AI-assisted cyberattacks represent a fundamentally new level of threat to national infrastructure
Story comments
Loading comments…