Yoido Full Gospel Church says data of 850,000 members may have leaked in cyberattack
In short
Yoido Full Gospel Church, South Korea's largest church, said data on about 850,000 members — names and dates of birth — may have been exposed after a cyberattack on its information system. The church said it was notified by the Korea Internet & Security Agency on Oct. 6 and that one of seven suspect files contained personal information; six did not. Senior pastor Lee Young-hoon apologised and the church said it had blocked external access, changed server passwords and would replace its firewall.
Read the full story 2 min read
Yoido Full Gospel Church, described in the documents as South Korea's largest church, said on Oct. 7 that the names and dates of birth of about 850,000 members may have been exposed after a cyberattack on its information system. The church said it was notified by the Korea Internet & Security Agency (KISA) at 3 p.m. on Oct. 6 of signs that its system had been compromised, and immediately began an emergency security review with outside security specialists, analysing suspect files and system access logs. [ 1 , 2 , 3 , 5 ]
The church said that of seven suspect files, six — covering transfer records between parishes, appointments to church positions and baptism records — contained no personal information. One file, a member information change history, did contain some personal data, the church said. According to reports citing the church, that file held the names and dates of birth of 850,000 people, including 2,629 resident registration number change records, 3,964 phone number change records and 7,202 address change records. Past donation records were also among the suspect files, but the church said these contained only voucher numbers, amounts and descriptions, not personal information. [ 1 , 2 , 3 , 5 ]
The church said it was notifying affected members of the exposure in line with relevant laws and procedures. It said it had blocked external access, deleted malicious files and changed server and related account passwords, with a change of all user passwords under way, and that it would replace its existing firewall and work with security firms on vulnerability analysis and further hardening. Yonhap reported that the external access block and server password change were carried out at 1 a.m. on Oct. 7. [ 1 , 2 , 5 ]
Senior pastor Lee Young-hoon apologised, saying “the responsibility to safely manage and protect the precious personal information of members lies with the church” and that he felt “heavy responsibility” as senior pastor for causing members concern. He said the church took the matter seriously, would actively cooperate with the investigations and verification procedures of relevant authorities, and would take all necessary measures to prevent a recurrence. [ 1 , 2 , 5 ]
The incident came to light after cybersecurity firm Oasis Security said it had identified large volumes of church member data on an overseas attacker server, including data from two large South Korean churches. Besides Yoido Full Gospel Church, Sarang Church in Seoul's Seocho district was also hacked, according to that account. The documents do not name any attacker or give further details on the Sarang Church case. [ 1 , 2 ]
Outlets differed slightly in how firmly they described the leak: some reported that the data had been leaked, while the church and other reports described it as suspected, pending analysis of the files believed to have been exposed. The documents do not specify how many individuals' resident registration numbers, phone numbers or addresses were actually exposed. [ 1 , 2 , 3 , 5 ]
Why it matters
The incident concerns the personal records of about 850,000 members of South Korea's largest church, and church records can include resident registration number, phone and address change histories. A cybersecurity firm has said data from two large churches was found on an overseas attacker server, which the church says it is still investigating with outside experts and regulators.
Key facts
- Yoido Full Gospel Church said it suspects the leak of names and dates of birth of about 850,000 members after a cyberattack on its information system. [ 1 , 2 , 3 , 4 , 5 ]
- The church said it was notified by the Korea Internet & Security Agency on Oct. 6 at 3 p.m. of signs of an intrusion. [ 1 , 3 ]
- Of seven suspect files, six contained no personal information; one — a member information change history — did, the church said. [ 1 , 2 , 5 ]
- The member information change history included 2,629 resident registration number change records, 3,964 phone number change records and 7,202 address change records, according to reports. [ 3 , 5 ]
- Past donation records in the suspect files contained voucher numbers, amounts and details but no personal information, the church said. [ 1 , 3 , 5 ]
- Senior pastor Lee Young-hoon apologised, saying responsibility for protecting members' personal information lies with the church. [ 1 , 2 , 5 ]
- Cybersecurity firm Oasis Security said it found large volumes of church member data on an overseas attacker server, and that Sarang Church in Seoul's Seocho district was also affected. [ 1 , 2 ]
Confirmed by several sources
- Yoido Full Gospel Church announced on Oct. 7 that the personal data of about 850,000 members may have been exposed in a cyberattack. [ 1 , 2 , 3 , 4 , 5 ]
- The church said it began an emergency security review after being notified by KISA of signs of an intrusion into its information system. [ 1 , 2 , 3 , 5 ]
- The church said six of seven suspect files contained no personal information, while one member information change file did. [ 1 , 2 , 5 ]
- Senior pastor Lee Young-hoon issued an apology and said the church would cooperate with authorities and strengthen its information protection systems. [ 1 , 2 , 5 ]
- Oasis Security said it identified church member data on an overseas attacker server and that a second large church, Sarang Church in Seocho district, Seoul, was also hacked. [ 1 , 2 ]
Still unclear
- Whether the data of 850,000 members was actually leaked or only suspected of being leaked. Some outlets report the leak as confirmed, while the church and others describe it as suspected, based on analysis of files thought to have been exposed.
- The scale and status of the reported breach at Sarang Church in Seoul's Seocho district. Only two documents mention it, and neither gives details of how many records or what data were involved.
- How many individuals' resident registration numbers, phone numbers or addresses were actually exposed. The documents give counts of change records in one file (2,629, 3,964 and 7,202) but do not say how many people those records concern or confirm public exposure.
- Who was behind the attack. The documents refer only to an overseas attacker server identified by a security firm, without naming a group or country.
What local media are saying
Timeline, local time
- KISA notifies Yoido Full Gospel Church of signs of an intrusion into its information system. [ 1 , 3 ]
- The church blocks external access and changes server passwords as an additional response measure. [ 1 ]
- Yonhap reports the church's announcement that data on 850,000 members may have leaked. [ 1 ]
- Seoul Economic Daily and Dong-A Ilbo publish reports on the suspected leak. [ 2 , 3 ]
- Chosun Ilbo reports the suspected leak, citing the church's press release. [ 4 ]
- Kyunghyang Shinmun reports the leak, citing the church's press release. [ 5 ]