SBS NEWS

Exclusive: Over One Million Pieces of Sensitive Data Leaked from Two Major Churches


Add SBS News to Google preferred sources
Show video

[Anchor]

Amid growing fallout from a series of hacking incidents, suspected cyberattacks have hit two major churches in South Korea. Personal information of churchgoers, along with sensitive details such as donation histories, is believed to have been compromised. Circumstances suggest that artificial intelligence was also utilized in these latest attacks.

We will first bring you an exclusive report by Reporter Hong Yeongjae, and then discuss the details further.

[Reporter]

Last month, while tracking multiple IP addresses suspected of being used in cyberattacks, a domestic security firm discovered an attacker's server containing massive amounts of personal information and hacking logs.

The source of the personal data on the server was found to be the integrated information system of Yoido Full Gospel Church in Seoul, which boasts the largest registered congregation in the country with 500,000 members.

Recorded as having been stolen in August, the leaked data includes up to two years of update logs for 960,000 church members' names, addresses, and phone numbers, as well as sensitive records such as donation histories spanning from 1993 to 2019.

[Kim Geun-yong / CEO, Oasis Security: The code 'X' following mis.fgtv.com indicates the webshell path—a malicious file—where the hacker had already successfully executed an attack. A church in South Korea was attacked, and files were leaked like this.]

Hacking materials targeting Sarang Community Church in Seocho-gu, Seoul, were also discovered.

Similarly, names, addresses, and phone numbers of 286 staff members including the senior pastor, and 89,000 churchgoers, which were stolen from the church's personnel information system last August, were found in bulk.

There were also traces suspected of utilizing artificial intelligence during the hacking process.

Logs detailing the attack process featured the expression "sub-agent," meaning an AI that performs commands, and an "attack handover report" was found on the server, summarizing hacking results, internal system structures, and account information.

[Nam Kyeong-heon / Executive Director, Oasis Security: The contents analyzed by the AI were very well documented in a way humans could understand, and a vast amount of data was analyzed, spanning hundreds of such documents.]

The security company reported the signs of the hacking incident to security authorities last month, and the Korea Internet & Security Agency recently notified the two churches of the fact.

Both Yoido Full Gospel Church and Sarang Community Church stated that they would ascertain the facts and implement security measures to prevent further damage.

(Photo: Shin Jin-soo, Bae Moon-san, Kang Dong-chul | Video Editing: Yoon Tae-ho)

---

[Anchor]

Economy Desk Reporter Hong Yeongjae is here with us in the studio.

Q. An 'AI Hacker' again?

[Reporter Hong Yeongjae: As I just reported in the news segment, hundreds of attack handover reports were found. The volume was massive and the format was consistent. The security industry stated that hackers utilizing AI recently often instruct AI to write reports of this form to receive results. In recent financial sector hacking logs, circumstances of using an AI tool called Artex were discovered. Judging by the report structure and format, it is estimated that a different low-cost AI model was used in this church hacking. There is also no overlap with the IP addresses used in the financial sector hacking, so although the timing is similar, they are seen as different entities.]

Q. Did they attack other churches as well?

[Reporter Hong Yeongjae: Analyzing the files remaining on the attacker's server, a total of 197 login attempts targeting domestic churches and denominations were found. So far, actual infiltration and information leakage have been confirmed only at the two locations: Yoido Full Gospel Church and Sarang Community Church. The security firm that verified the hacking is still conducting additional analyses on whether other churches were successfully breached or if it led to actual personal information leakage. In the case of churches or religious organizations, they tend to have relatively lower levels of professional security personnel or investment compared to general corporations, raising the possibility that attackers targeted these vulnerabilities.]

Q. Possibility of additional damage to followers?

[Reporter Hong Yeongjae: Since the victims are church members, the possibility of phishing scams referencing church relations or donation histories cannot be ruled out. In this incident, the Korea Internet & Security Agency notified the churches of the damage, but religious organizations are for non-profit purposes and thus do not fall under providers of information and communications services, meaning they are not subject to mandatory reporting of cyber breach incidents. However, as in this case, major religious organizations hold sensitive information on hundreds of thousands of people, so when a hacking incident occurs, damage comparable to that of large conglomerates can happen. Evaluations suggest they are placed in a blind spot for cybersecurity management handling personal information.]

※

※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Hong Yeongjae View More Articles
AD
AD
AD
AD