BREACH WATCH BRIEF High 🏦 Breach

Hackers Breach Two South Korean Megachurches, Exposing Data of Up to 850,000 Members

Two of South Korea's largest Protestant churches suffered cyberattacks that led to the theft of personal, financial, and internal records for hundreds of thousands of congregants. The breach highlights gaps in access control and privileged account management, underscoring the need for continuous control assurance.

SeverityHigh
Type🏦 Breach
ConfidenceHigh
ReportedOct 8, 2026
Other / Unknown Religious organizations with large member databases Vulnerability Exploit

What happened

Hackers compromised servers at Yoido Full Gospel Church and SaRang Church, installing a web shell to gain administrator-level access and using leaked passwords and application flaws to infiltrate SAP systems. They exfiltrated over 47 GB of data, including personal details, payroll, and internal communications.

Why it matters for trust and compliance

  • The incident demonstrates the critical importance of robust access‑control policies, privileged‑account monitoring, and evidence‑driven audit trails to satisfy multiple framework requirements.
  • Demonstrates need for continuous monitoring of privileged access
  • Provides evidence for audit readiness around identity governance

Who is affected

Religious organizations with large member databases

Recommended actions

  1. Conduct a privileged‑account review and enforce MFA for all admin accounts
  2. Deploy continuous web‑shell detection and log monitoring
  3. Update and patch internal applications, and rotate compromised credentials

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.