Attackers breached two of South Korea's largest churches. Yoido Full Gospel Church in Yeongdeungpo and Sarang Community Church in Seocho-gu, Seoul, have both started emergency security reviews. Korean threat intelligence firm Oasis Security found the stolen church data on an overseas server used by the attackers. The firm says the server held about 960,000 member records, 330,000 donation records and 47.3GB of internal data linked to Yoido Full Gospel, plus records on about 89,000 members and 286 staff linked to Sarang. Yoido Full Gospel's own internal analysis gives a lower figure: about 850,000 congregants whose names and dates of birth may have leaked, according to The Herald Business. The two churches say they are still working out what happened, and the record counts are not settled.
What Happened
Oasis Security says it was tracking IP addresses tied to recent attacks when it found an attacker server holding hacking tools, access logs, stolen credentials and stolen files. SBS reports that this happened last month. The firm said on October 6 that some of the data on that server came from two large Korean religious institutions. Yonhap and other outlets later named them as Yoido Full Gospel Church and Sarang Community Church.
Both Seoul Economic Daily and SBS report that the logs date both intrusions to August 2026. Oasis Security says that at both churches, the attacker first got into a system exposed to the outside and then moved to other internal systems. Because real church files sat on the attacker's server, the firm concludes the data was taken out of the churches' networks, not just accessed.
Yoido Full Gospel said in a press release that the Korea Internet & Security Agency (KISA) notified it of a suspected breach at 3 p.m. on Tuesday, October 6. The church says it started an emergency review straight away and brought in outside security firms. In comments carried by Maeil Business/Yonhap, the church said it takes the matter "seriously," will cooperate with investigators, and will review and strengthen its information protection systems. Sarang Community Church also said it had found signs that personal information may have leaked and is working to prevent further damage.
What Was Taken
Yoido Full Gospel Church. Accounts of how much was taken and what kinds of data it included do not agree:
- Member records: Oasis Security puts the figure at about 960,000 member records updated over the past two years. Seoul Economic Daily, Yonhap, ChosunBiz and ZDNet Korea all report this number. SBS reported "nearly 96,000." That is probably a transcription error, but it has not been confirmed either way. The church itself says one file held the names and dates of birth of about 850,000 congregants, according to The Herald Business. So the reported figures range from 850,000 (the church) to 960,000 (Oasis Security).
- Data types: Seoul Economic Daily and ZDNet Korea, citing Oasis, say the records include names and resident registration numbers. SBS describes names, addresses and phone numbers. The church says six of the seven suspected leaked files (parish transfers, appointment histories and baptism records) held no personal information. It says the seventh, a log of changes to congregant information, held names, dates of birth and 2,629 entries recording changes to resident registration data. The church's account and Oasis's disagree on how many people had resident registration numbers exposed. That difference matters a great deal for the risk to members.
- Donation records: Oasis Security reports about 330,000 member offering records. SBS describes donation histories covering 1993 to 2019.
- Internal records: About 68,000 electronic approval documents, 14,706 internal messenger conversations, and NAS file-server business documents, according to ZDNet Korea. Oasis puts the total at about 47.3GB.
The church describes seven files. Oasis describes a 47GB haul that includes approvals and messenger logs. The two accounts have not been reconciled.
Sarang Community Church. Oasis Security found personal information on about 89,000 members, including names, addresses and phone numbers, along with records on 286 staff and officials, including the senior pastor. ZDNet Korea adds that staff photos were taken from the church's SAP portal, and that staff names, phone numbers and bank account details were taken from a system linked to the church's university ministry. The church has not given its own count.
Why It Matters
Large religious institutions hold the same kinds of sensitive data as big companies: national ID numbers, financial giving histories, staff banking details and internal communications. They often have far less security maturity than a company of that size would. In South Korea, leaked resident registration numbers are especially damaging because they are lifelong identifiers that are hard to change. Donation histories also reveal a person's religious affiliation and finances, which makes them useful for targeted fraud and social engineering.
The infrastructure behind the attack matters too. Seoul Economic Daily, Yonhap and ZDNet Korea all report Oasis Security's finding that the attacker staged and moved the church data using a MinIO administrator account stolen in an earlier breach of a U.S.-based religious content and streaming platform. The firm calls this evidence that the incidents may be linked rather than separate. Yonhap cautions that infrastructure reuse alone does not prove the same actor was behind each attack. That platform has not been publicly named.
SBS separately reports that the attack logs contained the term "sub-agent," which it says suggests an AI agent was carrying out commands. Yonhap places the incident within a wave of AI-assisted attacks on Korea's financial sector. Only SBS reports the "sub-agent" evidence, and it should be treated as unconfirmed.
The Attack Technique
All of the technical detail below comes from Oasis Security's analysis of the attacker's server, mostly as reported by ZDNet Korea. Neither church has confirmed it.
Yoido Full Gospel Church
- Initial access: A web shell on the church's ERP server. SBS quotes Oasis CEO Kim Geun-yong naming a path on mis.fgtv.com as the location of the web shell.
- Privilege escalation: The attacker gained sysadmin rights on the MSSQL database behind the ERP system.
- Lateral movement: The attacker used database admin rights to reach connected internal services. Account credentials found in internal configuration files gave access to SMB shares on the NAS and to file servers.
- Exfiltration: Database dumps and NAS documents were staged internally, then sent to outside MinIO object storage.
Sarang Community Church - Initial access: A login to the groupware server using credentials apparently obtained in advance. How those credentials were obtained has not been disclosed. - Privilege escalation: Authentication and authorization flaws, including an IDOR (Insecure Direct Object Reference) in the church's SIMS system, gave the attacker other users' data and administrator-level accounts. - Lateral movement: The groupware's single sign-on gave access to the SAP portal without another login. From there the attacker reached a system linked to the university ministry.
Both intrusions follow the same pattern: get into one exposed application, escalate privileges, then use trust between connected systems (shared database credentials, credentials stored in config files, SSO) to reach everything else.
What Organizations Should Do
- Hunt for web shells on internet-facing ERP and web servers. Check web roots for unexpected script files and look for unusual child processes spawned by web server accounts. Compare against known-good baselines.
- Remove high-privilege database accounts from applications. ERP and web applications should not connect to MSSQL as
sysadmin. Disablexp_cmdshell, and alert on privileged logins from application hosts. - Remove credentials stored in plaintext. Audit configuration files for embedded NAS, SMB and database passwords, move them to a secrets manager, and rotate everything that was exposed.
- Treat SSO as a path for lateral movement. Require MFA on groupware and portals, scope SSO trust so that one session cannot reach finance or HR systems, and require step-up authentication for sensitive applications.
- Test authorization logic. Check internal web applications for IDOR and broken access control on every object request, not just at login.
- Watch for bulk data leaving the network. Alert on large transfers to object storage endpoints such as MinIO/S3 and to unfamiliar overseas IP addresses. Limit outbound traffic from servers to approved destinations.
Sources: Hackers Hit Two of Korea's Largest Churches; 960,000 Records Expose... | Exclusive: Over One Million Pieces of Sensitive Data Leaked from Tw... | Two Large Korean Churches Breached, Member and Donation Data Expose... | Yoido Full Gospel Church suspects data on 850,000 members leaked; S... | 대형 교회 2곳도 해킹 피해…"교인 정보 100만건 유출 가능성"(종합) | Hackers breach South Korea megachurches, expose up to 1 million rec... | 국내 대형교회 2곳 해킹 당했다...33만건 교인 헌금 정보 등 유출 - ZDNet korea | 대형 교회 2곳 사이버 공격 정황…교인정보 대규모 유출 가능성 연합뉴스