Summary
- The Yoido Full Gospel Church in Seoul has reported a potential data breach affecting 850,000 members, with sensitive information such as names, birth dates, and records of changes to personal information possibly compromised.
- Oasis Security, a cybersecurity firm, discovered the data on an overseas server, which also contained attack logs indicative of AI sub-agents, although the precise function of AI in the breach is still not fully understood.
- Another megachurch in Seoul, Sarang Church, has reportedly lost records of around 89,000 members and 286 employees, as South Korean authorities investigate suspected AI-assisted cyberattacks on financial institutions, including Shinhan Bank.
The Yoido Full Gospel Church, recognized as one of the largest congregations globally, announced on Wednesday that personal data belonging to 850,000 members might have been compromised.
Upon initial investigation, the church found that the stolen data included names, birth dates, and a detailed log of modifications made to members' records. "The file contained 2,629 changes to resident registration numbers, 3,964 changes to phone numbers, and 7,202 changes to addresses," the church stated.
On Tuesday afternoon, South Korea's internet security agency, KISA, alerted the church about the suspected breach. In response, the church has restricted external access to its systems, updated server passwords, and started notifying affected members.
Oasis Security uncovered the compromised data on an overseas server that also contained logs of attacks and account information related to both Yoido and Sarang Church. This discovery occurred in September while the firm was investigating internet addresses associated with suspected cyberattacks.
Sarang Church's data breach is smaller in scale, affecting approximately 89,000 member records and 286 employee records, including that of the senior pastor. According to reports, the data theft occurred in August, prompting the church to establish an emergency task force and report the incident to relevant authorities.
Oasis Security noted that the attack logs indicate the involvement of AI sub-agents, which are programs launched by an AI model to perform specific tasks. The churches are currently trying to understand how the attackers infiltrated their systems, and the exact involvement of AI remains ambiguous.
South Korean President Lee Jae Myung confirmed on Tuesday that AI is thought to have played a role in recent cyberattacks on commercial banks in the country. The breach at Shinhan Bank reportedly compromised personal details, including names, phone numbers, annual income, and borrowing limits of about 25,000 customers, prompting an emergency inspection by the financial regulator.
In light of the breach, the Yoido Full Gospel Church plans to upgrade its firewall and enlist security firms to identify potential vulnerabilities while continuing to inform the 850,000 members whose data may have been affected.