Data from Yoido Full Gospel Church, Sarang Church found on external server: report
At least two of South Korea’s largest churches appear to have suffered data breaches as a wave of cyberattacks, potentially involving artificial intelligence, continues to sweep the country.
Yoido Full Gospel Church in Yeouido, billed as the world’s largest Protestant church by registered membership, said Wednesday that its internal review found that the names, dates of birth and other personal details of 850,000 members may have been leaked.
The announcement followed an SBS TV report the previous day on suspected data breaches at two megachurches in Seoul, the other being Sarang Church in Seocho-gu.
According to the report, cybersecurity firm Oasis Security found what appeared to be stolen data from both churches on an external server, along with logs suggesting the alleged attackers may have used AI.
Yoido Full Gospel Church said it launched an emergency security review after the Korea Internet and Security Agency notified it of a suspected breach at 3 p.m. Tuesday. The church worked with outside cybersecurity specialists to examine the potentially leaked data and system access logs.
Six of the seven datasets examined contained no personal information. These included records of members moving between parish districts, appointments to church positions and baptisms.
The seventh dataset, a log of changes to members’ personal details, contained names, dates of birth and updated histories for 850,000 people. It included 2,629 entries recording changes to resident registration numbers, 3,964 to phone numbers and 7,202 to addresses, according to the church.
As part of its response, the church said it had blocked external access to its systems and changed server passwords earlier in the morning. The church added that it planned to replace its firewall and work with security companies to identify system vulnerabilities and strengthen protection.
A cybersecurity firm found the server last month while tracing IP addresses linked to suspected cyberattacks. It reportedly held a large trove of personal data and attack logs. The records revealed where attackers had planted a web shell — a malicious file used to remotely access and control a server — in the church’s system.
The firm also found evidence that Sarang Church’s personnel database had been breached. Logs indicated that the data of some 286 employees, including the senior pastor, and about 89,000 church members were stolen in August.
On Tuesday, South Korean police launched a full-scale investigation into a series of suspected AI-assisted hacking attacks on financial institutions including Shinhan Bank that exposed the personal information of tens of thousands of people.
junheee@heraldcorp.com