
Two large South Korean churches have been hit by cyberattacks, with signs that member records, donation and accounting files and internal documents were leaked externally.
Oasis Security, a cyber threat intelligence firm, said on the 6th that it found traces of cyberattacks targeting two large religious institutions in South Korea after analyzing attack tools, access logs, account credentials and stored files left on an overseas attacker's server.
At Church A, the attacker used a web shell to penetrate the enterprise resource planning (ERP) server and then obtained database administrator privileges, according to the analysis. The firm also found signs that the attacker expanded access to other internal systems connected to the ERP.
On the overseas server, investigators found roughly 960,000 member records and about 330,000 donation records believed to be linked to Church A. The files were found to have been updated over the past two years. Also included were about 68,000 electronic approval documents and 14,706 internal messenger conversations, with the total volume of data reaching about 47 gigabytes.
At Church B, the attacker logged into the groupware system using account credentials believed to have been obtained in advance, then exploited system vulnerabilities to gain other users' information and even administrator-level accounts, according to the analysis. The attacker then used a single sign-on function to reach the ERP system and extract staff information and photos.
On the overseas server, investigators also found member records for about 89,000 people and 286 staff records believed to be linked to Church B.
The attacks on the two churches also showed links to infrastructure used in cyberattacks abroad. Investigators found traces indicating that an administrator account for an external storage server used in the breach of a religious content and streaming service in the U.S. had also been used to store or transfer files from the Korean churches.
Oasis Security said accounts stolen during the attack on that service, or related infrastructure, may later have been reused in the attacks on the Korean churches. Still, the firm said the evidence confirmed so far makes it difficult to conclude that the same actors were behind both the U.S. service breach and the attacks on the Korean churches.
"There is a need to review not only how core business systems such as human resources and accounting systems, groupware and databases are connected to one another, but also authentication and access management frameworks," Oasis Security said.






