Hackers Breach South Korean Churches, Exposing 1 Million Members’ Data
Key Takeaways Two prominent South Korean churches suffered significant data breaches, compromising over one million congregant records and extensive operational data. Attackers exploited web shells,...
Key Takeaways
- Two prominent South Korean churches suffered significant data breaches, compromising over one million congregant records and extensive operational data.
- Attackers exploited web shells, unsecured direct object reference (IDOR) vulnerabilities, and leaked credentials to gain deep access to ERP, groupware, and database systems.
- The stolen data includes sensitive personal details, financial records, employee information, and internal communications, posing substantial risks for fraud and targeted scams.
- The intrusions involved multi-stage campaigns, including database manipulation, lateral movement within networks, and data staging in cloud environments.
- Organizations must prioritize robust access controls, secure coding practices, regular vulnerability assessments, and prompt patching to defend against similar complex attacks.
Cybercriminals have successfully infiltrated the digital infrastructure of two major religious organizations in South Korea, leading to the exposure of personal data belonging to more than one million congregants. The breaches also compromised a vast trove of financial, administrative, and internal operational data, according to a detailed analysis.
Table Of Content
The investigations reveal a sophisticated attack methodology, leveraging a combination of web shells, previously leaked credentials, and critical weaknesses in access controls. These vulnerabilities provided pathways into interconnected systems, exposing highly sensitive information.
In one incident, attackers gained entry by deploying a web shell within the church’s enterprise resource planning (ERP) system. The other breach stemmed from the exploitation of leaked credentials combined with insecure direct object reference (IDOR) flaws present in groupware and membership management systems, enabling access to confidential records.
Analysts at OASIS uncovered the extent of this activity following the examination of files retrieved from a server controlled by the attackers. Their findings indicate a multi-stage campaign rather than a singular malware event, characterized by database access, internal network movement, and data staging in cloud environments. OASIS said in a report shared with Cyber Security News (CSN) that the compromised data encompassed congregant details, donation histories, payroll information, employee records, approval documents, chat logs, and identity verification data.
The compromise of such extensive and sensitive data from community organizations is particularly alarming, as it creates significant opportunities for criminals to execute identity theft, financial fraud, or highly personalized phishing campaigns. The precise number of unique individuals affected across both breaches remains under verification.
Detailed Analysis of the Breaches
Researchers collected forensic evidence from an attacker-controlled server located in the U.S. between August 28 and September 1, 2026. This server contained a range of malicious tools, exfiltrated data, and operator reports pertaining to both victim organizations.
First Church Intrusion: Web Shell to SQL Server Control
The initial breach at the first church began with the injection of a web shell into its ERP system. Attackers meticulously reverse-engineered the ERP application files, successfully decrypted crucial database settings, and subsequently achieved administrator-level access to the Microsoft SQL Server. Utilizing xp_cmdshell, a SQL Server feature that permits the execution of operating-system commands, the attackers then navigated laterally across linked systems within the church’s network.
This elevated access exposed a multitude of databases, including those managing members, accounting, access control, library resources, chat communications, and mail. The attackers circumvented existing database-monitoring controls, retrieved a MariaDB root password, and exploited hardcoded network-attached storage (NAS) credentials to access backup storage. This method of using a database as a pivot to compromise the underlying Windows host has been observed in other SQL Server attack investigations.
The data exfiltrated from this church included approximately 960,000 congregant records, updated within the preceding two years, complete with names and resident registration numbers. Additionally, the haul comprised roughly 330,000 donation records, 68,000 document creation records, over 14,000 chat logs, and 6,874 login accounts. In total, researchers recovered 47.3 GB across 13,939 files from a compromised MinIO bucket, which was used by the attackers to stage the stolen data.
Second Church Intrusion: Leaked Credentials and IDOR Exploitation
The second church fell victim to an earlier intrusion, primarily through the exploitation of leaked credentials and Insecure Direct Object Reference (IDOR) vulnerabilities within its EKP groupware and SIMS services. An IDOR flaw occurs when an application processes a user-supplied reference to a record without properly verifying that the requesting user has the necessary authorization to access that specific record.
This vulnerability mirrors similar unauthenticated API data exposures reported in other faith-related services. Leveraging an existing member session, the attackers were able to view other users’ plaintext PINs and reset a manager-privileged account. The compromised data from this church included approximately 89,000 congregant records, 383 employee records, 286 human resources entries, 96 employee photographs, and various approval documents. The investigation also identified exposed college-ministry APIs and cloud storage instances configured with unrestricted read and write permissions.
What You Should Do
- Remove Unauthorized Access Points: Immediately identify and eliminate any unauthorized web shells or backdoors on your systems.
- Rotate Credentials and Invalidate Sessions: Promptly change all exposed passwords and security tokens. Invalidate all active user sessions to force re-authentication.
- Audit Logs: Scrutinize ERP, database, NAS, and cloud logs for any unusual access patterns, large data exports, or connections to suspicious external infrastructure.
- Secure Credentials: Treat any credentials found in backups, application configurations, public code repositories, or exposed storage as compromised. Implement secure credential management practices.
- Restrict Database Privileges: Disable
xp_cmdshellin SQL Server instances where it is not absolutely essential. Implement least privilege for linked server access and segment database systems to limit lateral movement. - Monitor SQL Server Activity: Investigate any suspicious command execution under SQL Server service accounts, particularly activity that attempts to reach other internal hosts.
- Implement Robust Authorization Checks: For all web applications, ensure every request rigorously verifies both the user’s identity and their specific permissions to access the requested data record.
- Conduct Authorization Testing: Regularly perform authorization testing, enforce the principle of least privilege, and implement safer password-reset mechanisms to prevent IDOR vulnerabilities.
- Patch and Audit: Keep all software patched, audit sensitive system changes, and regularly rotate service account credentials.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.