SEOUL — Two of South Korea’s largest megachurches are investigating suspected cyberattacks that may have exposed sensitive information belonging to hundreds of thousands of members, with cybersecurity researchers finding signs that artificial intelligence may have played a role in the attacks.
The suspected breaches involve Yoido Full Gospel Church and SaRang Church, both in Seoul. Investigators found church-related data, attack records and account information on an overseas server believed to have been used by attackers.
Hundreds of Thousands of Records Potentially Exposed
At Yoido Full Gospel Church, investigators identified information involving as many as 850,000 members that may have been compromised, according to the church’s initial assessment.
The potentially affected information includes names and dates of birth, while some records contained changes involving national identification numbers, addresses and telephone numbers.
Security researchers also found approximately 330,000 donation records, information relating to roughly 960,000 member records updated over the past two years, tens of thousands of electronic approval documents and thousands of internal messaging records on an overseas server.
The church has blocked external access to affected systems, changed server passwords and begun notifying individuals who may have been affected while working with authorities and cybersecurity specialists.
SaRang Church Also Targeted
SaRang Church, located in Seoul’s Seocho district, also found evidence suggesting that its systems may have been compromised.
Security researchers identified information involving more than 89,000 church members, as well as records concerning 286 employees and officials.
The suspected attackers appear to have used compromised credentials and exploited vulnerabilities to expand access between interconnected systems. Investigators are examining whether information was actually removed from the systems and the full extent of any exposure.
The church has established an emergency response team, reported the suspected incident to authorities and launched its own investigation.
AI Clues Found in Attack Records
One of the most unusual elements of the investigation is evidence suggesting that AI tools may have assisted the attackers.
Cybersecurity researchers found references to “sub-agents” in attack logs, along with large numbers of highly structured reports documenting attack results, system information and compromised accounts.
The evidence does not establish that an autonomous AI system independently carried out the attacks. Rather, investigators believe AI tools may have been used by hackers to automate or organize parts of the intrusion and analysis process.
The discovery comes as South Korea investigates a broader wave of cyberattacks against financial institutions.
South Korea Faces Growing AI Cybersecurity Threat
South Korean President Lee Jae Myung said this week that AI appeared to have been used in recent hacking attacks against major banks and called for cybersecurity measures designed specifically for the AI era.
The financial-sector attacks have raised concerns that criminals could increasingly use AI to automate reconnaissance, analyze stolen information and accelerate other stages of cyberattacks.
However, investigators have not established that the church attacks and the recent bank attacks were carried out by the same group.
The latest incidents underscore the growing risks faced by organizations holding large amounts of personal information. Religious institutions can maintain extensive databases containing members’ contact details, donation histories, employment information and other sensitive records, making them potentially valuable targets for cybercriminals.
Authorities and security specialists are continuing to determine exactly how the church systems were breached, what information was accessed and whether additional organizations were affected.
For the hundreds of thousands of people whose information may have been exposed, the investigation could also raise concerns about follow-on threats such as phishing, impersonation and targeted scams using stolen personal or donation-related information.