Cyber & AI intelligence
Wasteland.
Briefs indexed3034
Issues31
Published Mondays07:30 CT
▣ Breach KOREAN-MEGACHURCHE 2026-10-07

Yoido Full Gospel and Sarang Churches: Web Shell and Credential Attacks Expose Member Data

"Attackers breached two of South Korea's largest churches. Yoido Full Gospel Church in Yeongdeungpo and Sarang Community Church in Seocho-gu, Seoul, have both started emergency security reviews. Korean threat…"

Attackers breached two of South Korea's largest churches. Yoido Full Gospel Church in Yeongdeungpo and Sarang Community Church in Seocho-gu, Seoul, have both started emergency security reviews. Korean threat intelligence firm Oasis Security found the stolen church data on an overseas server used by the attackers. The firm says the server held about 960,000 member records, 330,000 donation records and 47.3GB of internal data linked to Yoido Full Gospel, plus records on about 89,000 members and 286 staff linked to Sarang. Yoido Full Gospel's own internal analysis gives a lower figure: about 850,000 congregants whose names and dates of birth may have leaked, according to The Herald Business. The two churches say they are still working out what happened, and the record counts are not settled.

What Happened

Oasis Security says it was tracking IP addresses tied to recent attacks when it found an attacker server holding hacking tools, access logs, stolen credentials and stolen files. SBS reports that this happened last month. The firm said on October 6 that some of the data on that server came from two large Korean religious institutions. Yonhap and other outlets later named them as Yoido Full Gospel Church and Sarang Community Church.

Both Seoul Economic Daily and SBS report that the logs date both intrusions to August 2026. Oasis Security says that at both churches, the attacker first got into a system exposed to the outside and then moved to other internal systems. Because real church files sat on the attacker's server, the firm concludes the data was taken out of the churches' networks, not just accessed.

Yoido Full Gospel said in a press release that the Korea Internet & Security Agency (KISA) notified it of a suspected breach at 3 p.m. on Tuesday, October 6. The church says it started an emergency review straight away and brought in outside security firms. In comments carried by Maeil Business/Yonhap, the church said it takes the matter "seriously," will cooperate with investigators, and will review and strengthen its information protection systems. Sarang Community Church also said it had found signs that personal information may have leaked and is working to prevent further damage.

What Was Taken

Yoido Full Gospel Church. Accounts of how much was taken and what kinds of data it included do not agree:

The church describes seven files. Oasis describes a 47GB haul that includes approvals and messenger logs. The two accounts have not been reconciled.

Sarang Community Church. Oasis Security found personal information on about 89,000 members, including names, addresses and phone numbers, along with records on 286 staff and officials, including the senior pastor. ZDNet Korea adds that staff photos were taken from the church's SAP portal, and that staff names, phone numbers and bank account details were taken from a system linked to the church's university ministry. The church has not given its own count.

Why It Matters

Large religious institutions hold the same kinds of sensitive data as big companies: national ID numbers, financial giving histories, staff banking details and internal communications. They often have far less security maturity than a company of that size would. In South Korea, leaked resident registration numbers are especially damaging because they are lifelong identifiers that are hard to change. Donation histories also reveal a person's religious affiliation and finances, which makes them useful for targeted fraud and social engineering.

The infrastructure behind the attack matters too. Seoul Economic Daily, Yonhap and ZDNet Korea all report Oasis Security's finding that the attacker staged and moved the church data using a MinIO administrator account stolen in an earlier breach of a U.S.-based religious content and streaming platform. The firm calls this evidence that the incidents may be linked rather than separate. Yonhap cautions that infrastructure reuse alone does not prove the same actor was behind each attack. That platform has not been publicly named.

SBS separately reports that the attack logs contained the term "sub-agent," which it says suggests an AI agent was carrying out commands. Yonhap places the incident within a wave of AI-assisted attacks on Korea's financial sector. Only SBS reports the "sub-agent" evidence, and it should be treated as unconfirmed.

The Attack Technique

All of the technical detail below comes from Oasis Security's analysis of the attacker's server, mostly as reported by ZDNet Korea. Neither church has confirmed it.

Yoido Full Gospel Church - Initial access: A web shell on the church's ERP server. SBS quotes Oasis CEO Kim Geun-yong naming a path on mis.fgtv.com as the location of the web shell. - Privilege escalation: The attacker gained sysadmin rights on the MSSQL database behind the ERP system. - Lateral movement: The attacker used database admin rights to reach connected internal services. Account credentials found in internal configuration files gave access to SMB shares on the NAS and to file servers. - Exfiltration: Database dumps and NAS documents were staged internally, then sent to outside MinIO object storage.

Sarang Community Church - Initial access: A login to the groupware server using credentials apparently obtained in advance. How those credentials were obtained has not been disclosed. - Privilege escalation: Authentication and authorization flaws, including an IDOR (Insecure Direct Object Reference) in the church's SIMS system, gave the attacker other users' data and administrator-level accounts. - Lateral movement: The groupware's single sign-on gave access to the SAP portal without another login. From there the attacker reached a system linked to the university ministry.

Both intrusions follow the same pattern: get into one exposed application, escalate privileges, then use trust between connected systems (shared database credentials, credentials stored in config files, SSO) to reach everything else.

What Organizations Should Do

  1. Hunt for web shells on internet-facing ERP and web servers. Check web roots for unexpected script files and look for unusual child processes spawned by web server accounts. Compare against known-good baselines.
  2. Remove high-privilege database accounts from applications. ERP and web applications should not connect to MSSQL as sysadmin. Disable xp_cmdshell, and alert on privileged logins from application hosts.
  3. Remove credentials stored in plaintext. Audit configuration files for embedded NAS, SMB and database passwords, move them to a secrets manager, and rotate everything that was exposed.
  4. Treat SSO as a path for lateral movement. Require MFA on groupware and portals, scope SSO trust so that one session cannot reach finance or HR systems, and require step-up authentication for sensitive applications.
  5. Test authorization logic. Check internal web applications for IDOR and broken access control on every object request, not just at login.
  6. Watch for bulk data leaving the network. Alert on large transfers to object storage endpoints such as MinIO/S3 and to unfamiliar overseas IP addresses. Limit outbound traffic from servers to approved destinations.

Sources: Hackers Hit Two of Korea's Largest Churches; 960,000 Records Expose... | Exclusive: Over One Million Pieces of Sensitive Data Leaked from Tw... | Two Large Korean Churches Breached, Member and Donation Data Expose... | Yoido Full Gospel Church suspects data on 850,000 members leaked; S... | 대형 교회 2곳도 해킹 피해…"교인 정보 100만건 유출 가능성"(종합) | Hackers breach South Korea megachurches, expose up to 1 million rec... | 국내 대형교회 2곳 해킹 당했다...33만건 교인 헌금 정보 등 유출 - ZDNet korea | 대형 교회 2곳 사이버 공격 정황…교인정보 대규모 유출 가능성 연합뉴스