Hackers Used AI Agents to Raid a Megachurch's Database, Exposing 850,000 Members

Hackers Used AI Agents to Raid a Megachurch's Database, Exposing 850,000 Members

Summary

Yoido Full Gospel Church said data linked to as many as 850,000 members may have been stolen, including names, birth dates and records of changes to personal details. South Korea’s internet security agency alerted the church, which blocked outside access, changed server passwords and began notifying members. Cybersecurity firm Oasis Security found the data on an overseas server alongside attack logs and records from Seoul’s Sarang Church, where about 89,000 member and 286 employee records were exposed. Logs suggest the theft occurred in August, but the churches have not determined how attackers entered their systems or whether AI played a role. South Korean officials have separately said AI may have been used in recent bank hacks. Yoido plans to replace its firewall and hire security firms to investigate further.