Two of South Korea’s largest churches are investigating suspected cyberattacks that may have exposed personal information belonging to hundreds of thousands of congregants.
Yoido Full Gospel Church and SaRang Church in Seoul have launched emergency investigations after cybersecurity researchers found data, attack logs and account information linked to the churches on an overseas server.
The researchers also found signs suggesting artificial intelligence may have been used during the attacks.
The evidence included automated reports and references to “sub-agents”, raising the possibility that attackers used AI tools to help automate parts of the intrusion.
No specific AI model or hacking group has been publicly identified.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Up to 850,000 Yoido Church Members May Be Affected
Yoido Full Gospel Church said its internal analysis indicated that personal information belonging to as many as 850,000 registered members may have been exposed.
The affected records included names and dates of birth.
A smaller number also contained changes to national identification numbers, addresses and telephone numbers.
The church said a compromised file contained 2,629 changes involving resident registration numbers, 3,964 phone-number changes and 7,202 address changes.
South Korea’s resident registration number is a sensitive national identifier used across government and private-sector services.
Exposure of such information can increase the risk of identity theft, impersonation and targeted phishing.
Church Was Alerted by Korea’s Cybersecurity Agency
Yoido Full Gospel Church said it was notified by the Korea Internet & Security Agency on October 6 about suspicious activity involving its information system.
The church then began an emergency security inspection with an external cybersecurity organisation.
It reviewed access logs and the data believed to have been taken.
The church later apologised to members and said it was considering requesting a police investigation.
It has also started notifying affected individuals and taking steps to strengthen its systems.
SaRang Church Also Opens Emergency Probe
SaRang Church has separately established an emergency response task force.
The church has informed authorities and is investigating whether its own membership database was compromised.
Reuters reported that cybersecurity company Oasis Security found records connected to both churches while analysing infrastructure associated with suspected attacks.
The full scale of the SaRang Church exposure has not yet been publicly established.
That means the two incidents should not be treated as having identical victim counts.
Researchers Found Attack Data on Overseas Server
The investigation began after researchers identified a server outside South Korea containing attack-related material.
That server reportedly held personal data, account records and logs associated with multiple intrusions.
The material included information linked to the churches’ membership systems.
Researchers believe attackers exploited vulnerabilities in the systems used to manage church members.
Reuters reported that one affected membership environment may have involved nearly 89,600 user accounts.
It is not yet clear whether every account in that environment was accessed or had information stolen.
Why Researchers Suspect AI Was Involved
The most unusual part of the incident is the suspected AI connection.
Researchers found automated documentation describing attack activity and references to “sub-agents”.
That terminology is commonly associated with systems in which an AI agent can divide a larger objective into smaller tasks and assign those tasks to other software agents.
In a cyberattack, such tools could potentially help with reconnaissance, vulnerability analysis, documentation or repeated attempts against different systems.
However, the available evidence does not prove that an autonomous AI system independently carried out the attack.
The safer conclusion is that researchers found signs consistent with AI-assisted hacking.
AI Can Speed Up Attacks Without Inventing New Techniques
Artificial intelligence does not necessarily need to discover an entirely new vulnerability to make a cyberattack more dangerous.
Its value to attackers may come from speed.
AI tools can help analyse software, organise stolen information, generate scripts and automate repetitive reconnaissance.
That can allow a smaller number of attackers to target more systems in less time.
South Korean authorities are already examining whether similar methods were used during recent attacks against major financial institutions.
President Lee Has Raised AI Hacking Concerns
President Lee Jae Myung said on October 6 that AI appeared to have been used in recent cyberattacks on South Korean banks.
Those incidents affected financial institutions including Shinhan Bank, KB Kookmin Bank, Hana Bank and Woori Bank.
Authorities have not publicly established that the church attacks and bank attacks were carried out by the same individual or group.
But the timing has intensified concern about attackers using AI to automate vulnerability discovery and intrusion activity.
South Korea’s financial regulator has already asked banks to increase cybersecurity monitoring following the recent breaches.
Personal Data Can Become a Second Attack Vector
The immediate breach is only one part of the risk.
Data stolen from church membership systems could later be used for phishing and impersonation.
A criminal who already knows a person’s name, date of birth, phone number or address can make fraudulent communications appear much more convincing.
Church members may therefore receive calls or messages pretending to come from the church, banks or government agencies.
Attackers could also combine leaked information with data stolen from unrelated breaches.
Churches Can Hold Highly Sensitive Data
Religious organisations are not always viewed as high-value cybersecurity targets in the same way as banks or government agencies.
But large churches can hold extensive personal information.
Membership systems may contain names, addresses, family relationships, donation records, phone numbers and identification details.
Some reports on the South Korean incidents also said donation-related information appeared among the exposed records.
That makes large religious organisations attractive targets for both financially motivated criminals and intelligence-gathering operations.
No Hacker Group Has Been Identified
Neither the churches nor authorities have publicly attributed the attacks to a known cybercrime or state-backed group.
There is also no confirmed evidence linking the incident to North Korea.
That distinction is important because South Korean organisations are frequent targets of North Korean hacking operations.
Reuters reported separately in August that one North Korean hacking group had built its own AI tools to help automate cyberattacks and analyse stolen material.
That earlier research demonstrates the broader threat, but it should not be used as evidence of North Korean involvement in the current church attacks.
Investigation Is Still Developing
Both churches are continuing forensic reviews to determine what information was accessed and how attackers entered their systems.
South Korean cybersecurity authorities are also examining the infrastructure and evidence discovered by researchers.
The final number of affected individuals may change as those investigations continue.
More importantly, investigators will need to determine whether the apparent AI-related artefacts represent genuine use of autonomous AI agents or simply automated tools using AI-generated components.
What this means for you
People affected by the church breaches should be cautious of messages or calls that use genuine personal details to build trust. Knowing your name, address or date of birth does not prove that a caller is legitimate, especially after a large personal-data leak.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics