VYPR
breachPublished Oct 7, 2026· 1 source

South Korean Churches Hit by Data Breaches Exposing Over 1 Million Congregant Records

Two major South Korean churches have suffered significant data breaches, compromising the personal and financial information of over one million congregants.

Two prominent South Korean churches have fallen victim to sophisticated cyberattacks, resulting in the exposure of sensitive data belonging to more than one million congregants. The breaches, which occurred over a period of several weeks, compromised not only personal identification information but also extensive financial and administrative records.

Security researchers from OASIS identified the intrusions after analyzing data recovered from an attacker-controlled server. The investigation revealed a multi-stage campaign rather than a single malware event. Attackers employed a combination of techniques, including the use of web shells within enterprise resource planning (ERP) systems, the exploitation of leaked credentials, and the leveraging of insecure direct object reference (IDOR) flaws in groupware and membership management systems.

The first church was compromised through a web shell planted in its ERP system. Attackers were able to reverse engineer application files, decrypt database settings, and ultimately gain administrator access to the Microsoft SQL Server. Utilizing the xp_cmdshell feature, which allows the execution of operating system commands, they moved laterally across linked systems. This access enabled them to reach databases for member information, accounting, access control, library functions, chat logs, and email.

Further complicating the breach, the attackers bypassed database monitoring controls, recovered a MariaDB root password, and used hardcoded credentials found in network-attached storage (NAS) to access backup data. This allowed them to exfiltrate approximately 960,000 congregant records containing names and resident registration numbers, along with around 330,000 donation records, 68,000 document-creation records, over 14,000 chat logs, and 6,874 login accounts. The staged data, totaling 47.3 GB across 13,939 files, was found on a compromised MinIO bucket.

The second church experienced a breach initiated through leaked credentials and vulnerabilities in its groupware and membership systems, specifically exploiting IDOR flaws in EKP and SIMS services. An IDOR vulnerability allows an application to accept a user-controlled record reference without properly verifying the requester's authorization. Using a compromised member session, attackers were able to view other users' plaintext PINs and reset a manager-privileged account. This led to the exposure of about 89,000 congregant records, 383 employee records, 286 HR entries, 96 employee photos, and various approval documents.

Both intrusions highlight the complex pathways attackers can exploit, moving from initial internet-facing access to deep system compromise. The first breach progressed from ERP application access to database administration, remote command execution, and network storage, while the second leveraged weak authentication and authorization controls to traverse multiple services.

OASIS recommends that organizations remove unauthorized web shells, rotate compromised credentials and tokens, and invalidate active sessions. They also advise inspecting logs for unusual access patterns, large data exports, or connections to suspicious infrastructure. Disabling unnecessary features like xp_cmdshell, segmenting database systems, and implementing robust authorization checks for all web application requests are crucial mitigation steps.

The report also warns that the accelerating capabilities of AI can significantly shorten attacker workflows, reducing the time defenders have to detect and respond to intrusions before sensitive data is exfiltrated. This incident underscores the need for continuous vigilance and proactive security measures, especially for organizations holding large volumes of sensitive personal data.

Synthesized by Vypr AI