Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CyberXero Blends AI Tools Claude Code, PentAGI with Cobalt Strike for Attacks
October 7, 2026
CrowdStrike, AWS, NVIDIA Expand Cybersecurity Startup Accelerator
October 7, 2026
SonicWall Patches Critical Pre-Auth SSRF (CVE-2024-XXXX) in SMA1000
October 7, 2026
Home/Threats/Hackers Breach South Korean Churches, Exposing 1 Million Members’ Data
Threats

Hackers Breach South Korean Churches, Exposing 1 Million Members’ Data

Key Takeaways Two prominent South Korean churches suffered significant data breaches, compromising over one million congregant records and extensive operational data. Attackers exploited web shells,...

Sarah simpson
Sarah simpson
October 7, 2026 4 Min Read
3 0

Key Takeaways

  • Two prominent South Korean churches suffered significant data breaches, compromising over one million congregant records and extensive operational data.
  • Attackers exploited web shells, unsecured direct object reference (IDOR) vulnerabilities, and leaked credentials to gain deep access to ERP, groupware, and database systems.
  • The stolen data includes sensitive personal details, financial records, employee information, and internal communications, posing substantial risks for fraud and targeted scams.
  • The intrusions involved multi-stage campaigns, including database manipulation, lateral movement within networks, and data staging in cloud environments.
  • Organizations must prioritize robust access controls, secure coding practices, regular vulnerability assessments, and prompt patching to defend against similar complex attacks.

Cybercriminals have successfully infiltrated the digital infrastructure of two major religious organizations in South Korea, leading to the exposure of personal data belonging to more than one million congregants. The breaches also compromised a vast trove of financial, administrative, and internal operational data, according to a detailed analysis.

Table Of Content

  • Key Takeaways
  • Detailed Analysis of the Breaches
  • First Church Intrusion: Web Shell to SQL Server Control
  • Second Church Intrusion: Leaked Credentials and IDOR Exploitation
  • What You Should Do

The investigations reveal a sophisticated attack methodology, leveraging a combination of web shells, previously leaked credentials, and critical weaknesses in access controls. These vulnerabilities provided pathways into interconnected systems, exposing highly sensitive information.

In one incident, attackers gained entry by deploying a web shell within the church’s enterprise resource planning (ERP) system. The other breach stemmed from the exploitation of leaked credentials combined with insecure direct object reference (IDOR) flaws present in groupware and membership management systems, enabling access to confidential records.

Analysts at OASIS uncovered the extent of this activity following the examination of files retrieved from a server controlled by the attackers. Their findings indicate a multi-stage campaign rather than a singular malware event, characterized by database access, internal network movement, and data staging in cloud environments. OASIS said in a report shared with Cyber Security News (CSN) that the compromised data encompassed congregant details, donation histories, payroll information, employee records, approval documents, chat logs, and identity verification data.

The compromise of such extensive and sensitive data from community organizations is particularly alarming, as it creates significant opportunities for criminals to execute identity theft, financial fraud, or highly personalized phishing campaigns. The precise number of unique individuals affected across both breaches remains under verification.

Detailed Analysis of the Breaches

Researchers collected forensic evidence from an attacker-controlled server located in the U.S. between August 28 and September 1, 2026. This server contained a range of malicious tools, exfiltrated data, and operator reports pertaining to both victim organizations.

First Church Intrusion: Web Shell to SQL Server Control

The initial breach at the first church began with the injection of a web shell into its ERP system. Attackers meticulously reverse-engineered the ERP application files, successfully decrypted crucial database settings, and subsequently achieved administrator-level access to the Microsoft SQL Server. Utilizing xp_cmdshell, a SQL Server feature that permits the execution of operating-system commands, the attackers then navigated laterally across linked systems within the church’s network.

This elevated access exposed a multitude of databases, including those managing members, accounting, access control, library resources, chat communications, and mail. The attackers circumvented existing database-monitoring controls, retrieved a MariaDB root password, and exploited hardcoded network-attached storage (NAS) credentials to access backup storage. This method of using a database as a pivot to compromise the underlying Windows host has been observed in other SQL Server attack investigations.

The data exfiltrated from this church included approximately 960,000 congregant records, updated within the preceding two years, complete with names and resident registration numbers. Additionally, the haul comprised roughly 330,000 donation records, 68,000 document creation records, over 14,000 chat logs, and 6,874 login accounts. In total, researchers recovered 47.3 GB across 13,939 files from a compromised MinIO bucket, which was used by the attackers to stage the stolen data.

Second Church Intrusion: Leaked Credentials and IDOR Exploitation

The second church fell victim to an earlier intrusion, primarily through the exploitation of leaked credentials and Insecure Direct Object Reference (IDOR) vulnerabilities within its EKP groupware and SIMS services. An IDOR flaw occurs when an application processes a user-supplied reference to a record without properly verifying that the requesting user has the necessary authorization to access that specific record.

This vulnerability mirrors similar unauthenticated API data exposures reported in other faith-related services. Leveraging an existing member session, the attackers were able to view other users’ plaintext PINs and reset a manager-privileged account. The compromised data from this church included approximately 89,000 congregant records, 383 employee records, 286 human resources entries, 96 employee photographs, and various approval documents. The investigation also identified exposed college-ministry APIs and cloud storage instances configured with unrestricted read and write permissions.

What You Should Do

  • Remove Unauthorized Access Points: Immediately identify and eliminate any unauthorized web shells or backdoors on your systems.
  • Rotate Credentials and Invalidate Sessions: Promptly change all exposed passwords and security tokens. Invalidate all active user sessions to force re-authentication.
  • Audit Logs: Scrutinize ERP, database, NAS, and cloud logs for any unusual access patterns, large data exports, or connections to suspicious external infrastructure.
  • Secure Credentials: Treat any credentials found in backups, application configurations, public code repositories, or exposed storage as compromised. Implement secure credential management practices.
  • Restrict Database Privileges: Disable xp_cmdshell in SQL Server instances where it is not absolutely essential. Implement least privilege for linked server access and segment database systems to limit lateral movement.
  • Monitor SQL Server Activity: Investigate any suspicious command execution under SQL Server service accounts, particularly activity that attempts to reach other internal hosts.
  • Implement Robust Authorization Checks: For all web applications, ensure every request rigorously verifies both the user’s identity and their specific permissions to access the requested data record.
  • Conduct Authorization Testing: Regularly perform authorization testing, enforce the principle of least privilege, and implement safer password-reset mechanisms to prevent IDOR vulnerabilities.
  • Patch and Audit: Keep all software patched, audit sensitive system changes, and regularly rotate service account credentials.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerMalwarePatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

FBI Warns of Critical FortiBleed Attacks Exploiting Fortinet Firewalls and VPNs

Next Post

SonicWall Patches Critical Pre-Auth SSRF (CVE-2024-XXXX) in SMA1000

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Fake Cloudflare CAPTCHAs Spread LUNEXSTEALER to 100+ Websites
October 7, 2026
Critical Atlassian Jira RCE Exploit Released for CVE-2023-22524
October 7, 2026
Rockstar Games Suffers Data Breach, GTA VI Source Code Stolen
October 7, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us