Mega Church Data Heist

Close-up of map showing North and South Korea.
Photo: New Africa / Shutterstock

Two of South Korea’s biggest churches say member data may have been exposed after suspected hacks, and the numbers are massive.

Story Snapshot

  • Yoido Full Gospel Church says data tied to 850,000 members may be at risk.
  • Sarang Church records, including member and staff details, were reportedly found on an attacker’s server.
  • A security firm described a web shell break-in and database administrator access on church systems.
  • Early counts differ by outlet, but all agree the scale is large and serious.

What the churches say happened

Yoido Full Gospel Church said its internal review found that names, birth dates, and other personal details tied to about 850,000 members may have been leaked. The church added that some personal information appeared in the “modification history” of member records. That matters because change logs can carry names, addresses, and even identification updates in one place, which simplifies theft at scale. Sarang Community Church-linked data was also reported on an attacker’s server, including members’ names, addresses, and phone numbers.

Coverage across Korean and English outlets converged on the same core story: two major churches are probing suspected cyberattacks and large-scale exposure of sensitive member information. Reports described hundreds of thousands of records across membership and donation-related systems. The consistency across outlets on the who, the what, and the high-level scope makes the incident hard to dismiss as rumor. One brief caveat is that the precise totals vary by source in these first reports.

How attackers reportedly got in

Independent analysis cited by multiple reports said a security team found a web shell on a church enterprise resource planning server. A web shell lets an attacker run commands remotely, move laterally, and pull data in bulk. The analysis also said the attacker gained database administrator rights. That access level allows queries, exports, and account changes that mask tracks. This path aligns with the data now in question: membership files, change histories, and offering-related records.

Investigators said the attacker’s server held data linked to both churches. For Sarang Church, reporting described about 89,000 member records with names, addresses, and phone numbers, plus records for 286 staff and officials, including the senior pastor. For Yoido, reporting pointed to files that match membership system outputs and logs. These details match what a web shell and administrator access would expose first: central databases and the audit trails around them.

Why the numbers differ and what still matters

Different outlets cited totals that range from tens of thousands to hundreds of thousands. Some counts likely describe unique people; others may include update logs, duplicate entries, or multiple systems over time. Early variance is common when teams piece together server finds, audit logs, and partial exports. The core fact remains the same: both churches are responding to suspected breaches that reach across member and donation-related data, which is sensitive in South Korea’s cultural and legal context.

Members fear exposure of addresses, phone numbers, and donation histories because such data ties directly to identity and social life. Churches often manage family details, community roles, and giving records that reveal personal patterns. When attackers copy change histories, they capture a timeline of who moved, who changed numbers, and who updated identification fields. That trail is gold for fraudsters and for harassment campaigns alike. Institutions that collect such data must assume it is a target, not just an archive.

What smart containment should look like now

Leadership must execute three tracks at once. First, cut attacker access and rotate all administrator credentials with multi-factor authentication. Second, stand up clear member notification, with plain steps to freeze credit, change passwords, and watch for scams. Third, coordinate with law enforcement and privacy regulators to preserve evidence and structure recovery. These moves reflect basic stewardship: protect the flock, tell the truth fast, and harden the gates so it does not happen twice.

Conservative common sense points to a simple yardstick here. Institutions that collect data owe the same care to church rosters as banks owe to account files. That means least-privilege access, strong authentication for all admin accounts, tight logging, and vendor oversight. It also means transparent notice when things go wrong. People can accept that criminals exist. They will not accept silence or slow-walked facts when their families’ data is at stake.

Sources:

asiae.co.kr, en.sedaily.com, news.sbs.co.kr