AI-linked breach at Seoul megachurch may have exposed 850,000 member records

AI-linked breach at Seoul megachurch may have exposed 850,000 member records

N
News Editor
2026-10-07 19:10:31
Yoido Full Gospel Church in Seoul said personal data tied to 850,000 members may have been stolen, in what appears to be one of the largest disclosed religious-organization data incidents in South Korea. The church said its initial review found names, dates of birth, and logs showing changes to member records, including 2,629 changes to resident registration numbers, 3,964 phone-number changes, and 7,202 address changes. South Korea’s internet security agency, KISA, alerted the church on Tuesday afternoon. The church then blocked outside access to its systems, changed server passwords, and started notifying affected members. Cybersecurity firm Oasis Security said it found the exposed data on an overseas server that also held attack logs and account details tied to Yoido and another Seoul megachurch, Sarang Church. Oasis said the logs point to activity by AI sub-agents and included long attack reports that appeared to be machine-written, though the entry path and AI’s exact role have not been determined. Sarang Church said about 89,000 member records and 286 employee records were affected. Separately, President Lee Jae Myung said recent hacks targeting South Korean commercial banks are also believed to have involved AI.

Yoido Full Gospel Church in Seoul said Wednesday that personal data tied to 850,000 members may have been stolen. Guinness once recognized the church as having the world’s largest congregation.

AI-linked breach at Seoul megachurch may have exposed 850,000 member records 2

Church review found names, birth dates, and record-change logs

The church said its initial review found names and dates of birth, along with logs showing changes members had made to their records.

In a statement, it said the file contained 2,629 changes to resident registration numbers, 3,964 changes to phone numbers, and 7,202 changes to addresses.

KISA alerted the church on Tuesday

South Korea’s internet security agency, KISA, flagged the suspected breach to the church on Tuesday afternoon. The church said it has since blocked outside access to its systems, changed server passwords, and begun notifying members.

Oasis Security found the data on an overseas server

Cybersecurity firm Oasis Security said it found the data on an overseas server that also held attack logs and account details linked to Yoido and a second Seoul megachurch, Sarang Church.

The company said it came across the data in September while tracing internet addresses tied to suspected attacks.

The Sarang Church exposure appears smaller: about 89,000 member records and 286 employee records, including the senior pastor’s. The logs suggest the data was stolen in August. Sarang Church has formed an emergency task force and reported the incident to authorities.

Logs show AI sub-agent activity, but the role of AI is still unclear

Oasis said the attack records show activity by AI sub-agents, or helper programs launched by an AI model to handle separate parts of a task. The logs also included long attack reports that appeared to be machine-written.

Even so, both churches are still working to determine how the intruders got in, and the exact role played by AI remains unclear.

President Lee also referenced AI in recent bank hacks

President Lee Jae Myung confirmed Tuesday that AI is believed to have been used in recent hacks targeting South Korean commercial banks.

According to local news reports, a breach at Shinhan Bank exposed names, phone numbers, annual income, and borrowing limits for about 25,000 customers. The financial regulator then opened an emergency on-site inspection.

Yoido plans firewall replacement and outside security review

Yoido Full Gospel Church said it plans to replace its firewall and bring in security firms to look for other weaknesses while it continues notifying the 850,000 members who may have been affected.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.