Church Giants Hacked – Donations Exposed?

Hacker wearing a hoodie with digital codes overlaying.
Photo: Shutterstock

Two of South Korea’s biggest churches say member data tied to hundreds of thousands of people may have been exposed after suspected cyberattacks.

Story Snapshot

  • Yoido Full Gospel Church says data tied to 850,000 members may be at risk.
  • Change-history files included names, birthdates, and other personal details.
  • Sarang Church data, including member contacts and staff records, was reportedly found on an attacker’s server.
  • A security firm described a web shell break-in and database administrator access.

What the churches reported, and why it matters

Yoido Full Gospel Church said an internal review found that names, dates of birth, and other personal details for about 850,000 members may have been leaked. The church said some of that personal data appeared inside change-history logs tied to the membership system. Those logs can reveal more than most people think. A change entry often holds the old value and the new value, which can expose a name, address, phone, or even a note about a status change when copied out of place.

Reports also pointed to Sarang Community Church. Data found on an external attacker server allegedly included details for about 89,000 members, such as names, addresses, and phone numbers, plus files on 286 staff and officials, including the senior pastor. Church staff and volunteer lists can carry sensitive role data, direct lines, and internal notes. That information can enable scams that feel personal, like fake donation requests or targeted texts that name clergy.

How the break-ins likely worked

Multiple reports cited Oasis Security describing a web shell planted on a church enterprise system. From there, the attacker reportedly reached the database and gained administrator-level privileges. A web shell is a small script that acts like a secret door. Once inside, an intruder can run commands, list files, and pull data. Administrator access often removes the last guardrail. It lets the attacker view tables, export records, and even alter logs to hide their tracks.

The coverage from Korean and English outlets converged on the core event: two major churches, suspected cyberattacks, and large-scale exposure of member and donation-related data. Some reports also referenced donation records and accounting data. Financial and giving histories carry extra weight in South Korea. These fields tie identity, faith, family, and money in ways that can drive blackmail, fraud, or social harm if exposed.

What the numbers mean for real people

Large congregations are fertile ground for social engineering. A list of names and birthdays fuels phishing. Add phone numbers and addresses, and criminals can try delivery scams or utility hoaxes. Insert donation details or parish roles, and the grift sharpens: fake appeals that look real, “pastor needs gift cards” texts, or spoofed accounting checks. The conservative common-sense response is simple: verify before you pay, and use two-factor logins for church apps, email, and banking.

For the churches, the lesson is also clear. Limit who can view member lists. Log every export. Keep change-history files away from public-facing systems. Enforce two-factor authentication for every administrator account. Segment networks so a single web server cannot reach the core database without extra checks. Back up systems often, and keep one backup offline. These steps protect privacy and stewardship, which are moral duties as much as technical tasks.

The timeline that led to public warnings

Media reports say a security team recovered attack tools and logs from an overseas server and linked them to the churches’ systems. The same reporting described administrator-level access and files tied to member records, update logs, and donation-related data. Yoido Full Gospel Church then issued a statement about 850,000 member records that may be affected and noted that some personal data was found in modification histories. Each action shows a standard response: find the breach path, lock down systems, and tell your community.

Early numbers in fast-moving cases often differ as teams sort unique people from log entries and duplicates. That happens because leaks can blend live records, backups, and update trails. The key point here is not the variance but the pattern: two megachurches, sensitive data categories, and credible signs of database-level access. The events fit a known breach playbook. First comes a quiet foothold. Next, the data mapping and export. Finally, the public warning when investigators confirm what left the building.

What to do next if you might be affected

Members should treat any unexpected call, text, or email about donations or private details as suspicious. Do not click links. Call a known church number to verify requests. Place a fraud alert with your mobile carrier and bank if you see odd activity. Rotate passwords on email and church-related apps. Use a password manager to set unique, strong passphrases. Ask your church about credit monitoring or identity protection, and check whether they offer new privacy controls for your records.

Sources:

asiae.co.kr, en.sedaily.com, chosun.com, news.sbs.co.kr