"Includes Some Addresses, Phone Numbers, and Resident Registration Numbers"
Younghoon Lee Says, "We Will Rigorously Strengthen Our Information Security System"

Amid a recent wave of hacking incidents across the financial sector and other industries involving the use of artificial intelligence (AI) tools, it has been confirmed that two major churches in Korea have also been exposed to cyberattacks. Yoido Full Gospel Church, the country's largest congregation and one of the victims, reported through its own analysis that the names and dates of birth of its 850,000 congregation members may have been compromised.


View of Yoido Full Gospel Church. Yoido Full Gospel Church

View of Yoido Full Gospel Church. Yoido Full Gospel Church

View original image

On October 7, Yoido Full Gospel Church announced through a press release that, "Upon being notified by the Korea Internet & Security Agency (KISA) at 3:00 p.m. the day before about indications of a breach of the church’s information systems, we immediately initiated an emergency security inspection and, together with an external security firm, analyzed the potentially leaked materials and system access logs."


The church added, "Of the seven suspected leaked data items, six—including records of parish transfers, appointments to church positions, and baptism history—contained no personal information. It was confirmed, however, that one record pertaining to revisions of congregation member information did include some personal data."


This log of changes to congregation member information contained the names, dates of birth, and details of changes for a total of 850,000 individuals. Among these were 2,629 changes to resident registration numbers, 3,964 changes to phone numbers, and 7,202 changes to addresses. The church added that, among the leaked data, historical offering records included transaction numbers, amounts, and details, but did not contain personal information such as names.


Yoido Full Gospel Church stated, "We are currently notifying affected congregation members of the leak in accordance with relevant laws and procedures," adding, "As of 1:00 a.m. today, we have enacted additional response measures, such as blocking external access and changing server passwords." The church also plans to replace its existing firewall to maintain the latest security standards, and is conducting a vulnerability assessment and additional security enhancements in collaboration with professional security firms.


Senior Pastor Younghoon Lee said, "It is the church’s responsibility to safely manage and protect your valuable personal information. As the senior pastor, I feel a heavy sense of responsibility and sincerely apologize for the concern this incident has caused to our members."


He continued, "We view this matter with the utmost seriousness. Along with fully cooperating with relevant authorities in their investigations, we will take all necessary measures to thoroughly strengthen our information security system so that such incidents do not occur again."


Previously, cybersecurity company OasisSecurity reported that it had discovered large volumes of congregation data from two major Korean churches stored on servers operated by foreign attackers. In addition to Yoido Full Gospel Church, Sarang Church in Seocho-gu, Seoul also fell victim to hacking.


According to OasisSecurity, in the case of Yoido Full Gospel Church, the attacker penetrated the enterprise resource planning (ERP) system server by exploiting a malicious program known as a web shell, and gained administrator access to the database used by the system. OasisSecurity further explained that the attacker appeared to use these privileges to access other internal systems and connected services.



The company reported that the foreign attack server contained approximately 330,000 records of congregation offerings believed to be related to Yoido Full Gospel Church, along with around 960,000 items of church member information updated over the past two years. In addition, roughly 68,000 electronic approval documents and 14,706 internal messenger chat logs—amounting to approximately 47.3GB of data—were also discovered.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing