
Two of South Korea's largest churches have launched emergency security reviews after signs emerged that hundreds of thousands of member records, along with offering and accounting data, may have been stolen in cyberattacks. The suspected breaches at Yoido Full Gospel Church and Sarang Community Church come as hacking incidents mount across the country, including in the financial sector.
Cyber threat intelligence firm Oasis Security said on the 6th that it found large volumes of data apparently linked to two major Korean religious institutions while analyzing servers used by overseas attackers.
From Yoido Full Gospel Church's integrated information system, the firm identified about 330,000 records of member offerings logged as having been stolen in August, as well as roughly 960,000 member records updated over the past two years. The data included personal information such as names and resident registration numbers, along with about 68,000 electronic approval documents and 14,706 internal messenger conversations. The total volume of data reached about 47.3 gigabytes.
According to Oasis Security's analysis, the attacker is believed to have used malicious software known as a web shell to penetrate the church's enterprise resource planning server, then obtained database administrator privileges. There were also indications the attacker expanded access to services connected to other internal systems.
In the case of Sarang Community Church, personal information on about 89,000 members — including names, addresses and phone numbers — was found on the attacker's server, along with data on 286 staff and officials, including the senior pastor.
In that case, the attacker is believed to have accessed the church's groupware using credentials obtained in advance, then exploited system vulnerabilities to gain administrator-level privileges. There were also signs the attacker reached the ERP system through a single sign-on function that allows access to multiple systems with one login.
Oasis Security told Yonhap News Agency that organizations need to examine how core business systems such as human resources and accounting platforms, groupware and databases are connected to one another, as well as their authentication and access control structures.
Churches Respond: Scope of Any Actual Breach Still Being Verified

Both churches have begun responding. Yoido Full Gospel Church said in a statement that day that it had been notified by the Korea Internet & Security Agency of suspected signs of a personal data breach involving its information systems.
The church said it is working with relevant authorities and security experts to establish the facts, and that it has begun an urgent security review and protective measures for its systems. It is also investigating whether an external intrusion occurred and how, as well as the types and scope of information actually affected.
On the possibility raised by the security firm that member records and past offering histories were leaked, the church said it is still verifying the claims. Yoido Full Gospel Church told Newsis it is checking the facts regarding the specific time period and scope involved, adding that it is difficult to state anything definitively at this stage while the investigation is under way.
If a data breach is confirmed, the church plans to report it to the authorities and notify affected members. It also intends to explain what it has learned so far and the steps it has taken during its Wednesday service.
Sarang Community Church likewise set up an emergency task force and reported the matter to the authorities after identifying signs of a possible data breach. It is investigating exactly how the incident occurred while taking steps to prevent further damage.
Oasis Security also raised the possibility that credentials or related infrastructure obtained in a breach of a U.S. religious content and streaming service were used in the attacks on the Korean churches. The firm said, however, that the evidence confirmed so far is not enough to conclude the attacks were carried out by the same party. The methods also differ from those used in recent cyberattacks on the financial sector, making it unlikely the same attacker was involved.






