Local Chorus
Местные новости из местных источников на вашем языке.

Translating into Русский. The English version is shown until it is ready.

Развивается

Two large Seoul churches show signs of cyberattack; member data feared leaked

🇰🇷 Южная Корея, Seoul 08:54 IT и софт Бизнес8 Техно Официальные обновлено 3 ч назад первым сообщил 서울신문

Коротко

An analysis by cyber threat intelligence company Oasis Security found evidence that two large South Korean churches were hit by cyberattacks, with member records, donation and accounting data and internal documents found on an overseas attacker server. The churches were identified in reports as Yoido Full Gospel Church in Yeongdeungpo district and Sarang Church in Seocho district, both in Seoul. Both churches said they were checking the facts and taking emergency security measures.

Читать полностью 3 мин чтения

Two large churches in Seoul show signs of having been hit by cyberattacks, according to an analysis by cyber threat intelligence company Oasis Security. The company said it examined attack tools, logs, stolen data and account credentials found on an overseas attacker server and found large amounts of member information linked to two major South Korean religious institutions, with real church-related data apparently transferred to the external server. Reports identified the two as Yoido Full Gospel Church in Yeongdeungpo district and Sarang Church in Seocho district. [ 2 , 3 , 5 , 9 , 11 ]

For Yoido Full Gospel Church, Oasis Security said an attacker used a webshell to penetrate an enterprise resource planning (ERP) server and gained administrator rights over its database, then reached other connected internal systems. The overseas server held about 960,000 member records updated over the past two years, about 330,000 donation records, some 68,000 electronic approval documents and 14,706 internal messenger messages — about 47.3GB in total, the company said. Maeil Business, citing an SBS report, said the server contained member names, addresses and phone numbers and donation records from 1993 to 2019, with the data presumed to have been taken in August. ZDNet Korea said the member records included names and resident registration numbers. [ 2 , 3 , 7 , 9 , 11 ]

At Sarang Church, the company said an attacker used credentials believed to have been obtained in advance to reach a groupware server, then exploited authentication and authorisation weaknesses, including an insecure direct object reference (IDOR), to reach other users' information and administrator-level accounts. The attacker used a single sign-on function to reach an SAP portal without a separate login and obtained employee information and photographs, the analysis said, and also collected names, phone numbers and account details from a university-linked system. About 89,000 member records and 286 staff records, including the senior pastor, were found on the overseas server, according to the reports. [ 2 , 3 , 9 , 11 ]

Oasis Security said it also found that an administrator account tied to the breach of a US-based religious content and streaming service was used to store and transfer the Korean church data, suggesting accounts or infrastructure from that earlier breach may have been reused. ZDNet Korea identified the reused account as a MinIO administrator account. The company said, however, that the evidence is not enough to conclude that the attacks had the same perpetrator. [ 2 , 3 , 5 , 9 ]

The Korea Internet & Security Agency notified the churches, according to the reports. Yoido Full Gospel Church said in a statement that it had been notified by KISA of suspected personal data leakage and was checking the facts with related agencies and security experts, while Sarang Church said it formed an emergency response team, reported to authorities and was taking steps to prevent further damage. Maeil Business said the security company had reported the suspected damage to security authorities last month. [ 7 , 11 ]

The reports came as a series of hacking cases in the financial sector, in which artificial intelligence tools are suspected of being used, drew attention, Yonhap and Maeil Business noted. Hankook Ilbo reported that the method used against the churches differed from the financial-sector attacks and that the same attacker was considered unlikely, while Yonhap said the evidence does not establish a link between the US platform breach and the church attacks. Yonhap, Seoul Shinmun, Hankook Ilbo and Korea Economic Daily also reported a possibility that up to, or more than, 1 million member records could have been leaked. [ 6 , 8 , 10 , 11 , 12 ]

Почему это важно

The case concerns two of South Korea's best-known large churches and data covering hundreds of thousands of members, which if confirmed would be one of the larger personal data leaks reported in the country. The reports also point to possible reuse of infrastructure from an earlier breach of a US religious streaming service, though the security company says the evidence does not establish a single attacker. For readers outside Korea, the case is mainly relevant as another example of attacks on religious organisations and their connected internal systems.

Ключевые факты

  • Oasis Security said it analysed attack tools, logs, stolen data and account credentials on an overseas attacker server and found large amounts of member information linked to two large South Korean religious institutions. [ 2 , 3 , 5 , 9 ]
  • Reports identified the two churches as Yoido Full Gospel Church in Seoul's Yeongdeungpo district and Sarang Church in the city's Seocho district. [ 3 , 7 , 11 ]
  • Data tied to Yoido Full Gospel Church on the server included about 960,000 member records updated over the past two years, about 330,000 donation records, some 68,000 electronic approval documents and 14,706 internal messenger messages, about 47.3GB in total. [ 2 , 3 , 9 , 11 ]
  • Maeil Business, citing an SBS report, said the server held member names, addresses and phone numbers and donation records from 1993 to 2019, with the data presumed to have been taken in August. [ 7 ]
  • Data tied to Sarang Church included about 89,000 member records and 286 staff records. [ 2 , 3 , 9 , 11 ]
  • Oasis Security said an administrator account from the breach of a US-based religious content and streaming service appeared to have been reused to store and transfer the domestic church data. [ 2 , 3 , 5 , 9 ]
  • Yoido Full Gospel Church said it was notified by the Korea Internet & Security Agency of suspected personal data leakage and was verifying the facts with authorities and security experts; Sarang Church said it formed an emergency team, reported to authorities and was taking steps to prevent further damage. [ 7 , 11 ]

Подтверждено несколькими источниками

  • Oasis Security said its analysis of an overseas attacker server found evidence of cyberattacks on two large South Korean religious institutions, with member data, donation and accounting material and internal documents apparently sent to the external server. [ 2 , 3 , 5 , 9 ]
  • The two churches were identified in reports as Yoido Full Gospel Church and Sarang Church. [ 3 , 7 , 11 ]
  • Data tied to Yoido Full Gospel Church found on the server included about 960,000 member records updated in the past two years, about 330,000 donation records, some 68,000 electronic approval documents and 14,706 internal messenger messages, about 47.3GB in total. [ 2 , 3 , 9 , 11 ]
  • Data tied to Sarang Church found on the server included about 89,000 member records and 286 staff records. [ 2 , 3 , 9 , 11 ]
  • Oasis Security said the evidence is not enough to conclude that the two church attacks had the same perpetrator, and that accounts or infrastructure from a US religious content and streaming service breach may have been reused in attacks on the Korean churches. [ 2 , 3 , 5 , 9 ]
  • The Korea Internet & Security Agency notified the churches, and both said they were checking the facts and taking security measures. [ 7 , 11 ]

Пока неясно

  • Who carried out the attacks. Oasis Security said the evidence is not sufficient to conclude the church attacks share the same perpetrator, and no outlet identified a suspect.
  • Whether artificial intelligence was used in the attacks. Maeil Business reported traces suggesting AI may have been used and said reports summarising hacking results and internal system structure were found on the attacker server; other documents do not mention this.
  • The exact number of affected members. Yonhap, Seoul Shinmun, Hankook Ilbo and Korea Economic Daily reported a possibility of up to or more than 1 million member records, while the figures found on the server were smaller and the churches said they were still verifying.
  • Whether the church attacks are connected to recent hacking cases in the financial sector. Hankook Ilbo reported the method differed from the financial-sector attacks and that the same attacker was considered unlikely, while Yonhap mentioned the financial-sector cases only as background.

Что пишут местные СМИ

Деловые СМИBusiness outlets led with the scale of the suspected leak, naming figures for member records, donation histories and internal documents, and highlighted the churches' emergency security measures. Several framed the case as following a wave of financial-sector hacking, and some reported a possibility of up to or more than 1 million leaked member records. [ 1 , 4 , 5 , 7 , 8 , 9 , 10 , 11 , 12 ]
Официальные источникиThe official wire service gave the most detailed reconstruction of the intrusion paths attributed to Oasis Security, listing the two churches as A and B, and stressed that the evidence does not allow a conclusion that the attacks had the same perpetrator, while noting the financial-sector hacking cases as background. [ 2 , 6 ]
Технологические СМИThe tech outlet provided the deepest technical account, naming both churches and describing the tools and techniques involved, including a webshell, database administrator rights, IDOR, single sign-on access to an SAP portal, NAS file shares and MinIO storage infrastructure. [ 3 ]

Хронология, местное время

  1. Newsis reports signs of hacking at two large churches and a message on protecting members' personal information and preventing further damage. [ 1 ]
  2. Yonhap reports, citing Oasis Security, that the two churches were attacked and that large-scale leakage of member information is possible. [ 2 ]
  3. ZDNet Korea names Yoido Full Gospel Church and Sarang Church and details the attack paths and stolen data. [ 3 ]
  4. Maeil Business, citing an SBS report, says the data is presumed to have been taken in August and that the security company reported the case to security authorities, with KISA notifying the two churches. [ 7 ]
  5. Hankook Ilbo reports the churches' emergency security checks and statements, and a possibility that information on 1 million members was leaked. [ 11 ]
  6. Korea Economic Daily reports a possible leak of up to 1 million member records. [ 12 ]