[Anchor]
As the fallout from recent hacking incidents continues to grow, suspected cyberattacks have now struck two major churches in South Korea. Personal information of churchgoers, along with sensitive data such as donation records, appears to have been compromised. Circumstances also indicate that artificial intelligence was utilized in this latest attack.
We will first bring you an exclusive report from reporter Hong Yeongjae, followed by a detailed discussion.
[Reporter]
Last month, while tracking multiple IP addresses suspected of being used in cyberattacks, a domestic security firm discovered an attacker's server containing massive amounts of personal information and hacking logs.
The personal data on the server originated from the integrated information system of Yoido Full Gospel Church in Seoul, which has the largest registered congregation in the country with 500,000 members.
The breach was recorded as having taken place last August, compromising nearly 96,000 records including the names, addresses, and phone numbers of church members updated over the past two years, as well as sensitive details such as donation history from 1993 to 2019.
[Kim Geun-yong / CEO, Oasis Security: mis.fgtv.com followed by the code 'X' is the path to the web shell (malicious file) where the hacker had already successfully launched an attack. A church in our country was attacked, and the files were leaked like this.]
Hacking materials targeting Sarang Community Church in Seocho-gu, Seoul, were also discovered.
The data, likewise pilfered from the church's personnel information system last August, contained en masse the names, addresses, and phone numbers of 286 employees, including the senior pastor, and 89,000 church members.
There were also traces pointing to the suspected use of AI during the hacking process.
The logs detailing the attack process featured the expression "sub-agent," implying an AI executing commands, and the server yielded an "attack handover report" summarizing the hacking results, internal system structures, and account credentials.
[Nam Gyeong-heon / Director, Oasis Security: The content analyzed by the AI was exceptionally well-documented for human comprehension, and a massive volume of data was analyzed, spanning hundreds of such documents.]
The security firm reported the suspected hacking incident to security authorities last month, and the Korea Internet & Security Agency (KISA) recently notified the two churches of the matter.
Yoido Full Gospel Church and Sarang Community Church stated that they would look into the facts and implement security measures to prevent further damage.
(Photo: Yonhap News / Reported by Shin Jin-soo, Bae Moon-san, and Kang Dong-chul; Video editing by Yoon Tae-ho)
---
[Anchor]
Economic Desk reporter Hong Yeongjae is here in the studio.
Q. An "AI hacker" once again?
[Hong Yeongjae: As just reported, hundreds of attack handover reports were found. The volume was massive, and the formats were consistent. The security industry notes that hackers utilizing AI recently often instruct AI to compile reports in this format to review the outcomes. Recent hacking logs from the financial sector revealed traces of an AI tool called Artex. Judging by the report structure and format, it is estimated that a different, lower-cost AI model was used in this church hack. There is also no overlap with the IP addresses used in the financial sector hacks, suggesting that while the timing is similar, it is a different actor.]
Q. Attacks on other churches as well?
[Hong Yeongjae: An analysis of the files left on the attacker's server revealed records of a total of 197 login attempts targeting churches and denominations nationwide. Thus far, actual intrusion and data leak circumstances have been confirmed only at the two locations, Yoido Full Gospel Church and Sarang Community Church. The security firm that identified the breach is still conducting further analysis to determine whether other churches were successfully hacked or if it led to actual personal information leaks. Since churches and religious organizations generally have lower levels of professional security staffing or investment compared to general corporations, it is suggested that attackers may have targeted these vulnerabilities.]
Q. Possibility of additional victim damage to church members?
[Hong Yeongjae: Because the victims are church members, the possibility of phishing scams referencing church personnel or donation history cannot be ruled out. In this incident, KISA notified the churches of the damage circumstances, but religious institutions are not subject to mandatory reporting for cyber breach incidents because they are non-profit and therefore do not qualify as information and communications service providers. However, as seen in this case, large religious institutions hold sensitive information on hundreds of thousands of people, meaning a hack can cause damage on par with major conglomerates. Experts point out that they are placed in a blind spot for cybersecurity management handling personal information.]
※ Please note: This article was translated by AI and may contain errors.
Exclusive: Up to Two Mega-Churches Hit in Suspected Hack, Compromising 1 Million Sensitive Records
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Trending Now
-
Police Investigate Alleged Leak of OB-GYN CCTV Footage, Including Patient Changing Scenes
-
Video News
Gwangju Pub Under Fire for Menu Item Mocking May 18 Victims
-
Video News
"Why Does He Look Like That?" Resigned Security Guard... Notice Posted in Apartment Complex
-
Video News
"My Child Was Bleeding, Yet They Fled"—Father Shares Update After Catching Hit-and-Run Suspect
-
70-Man Sentenced to 5 Years in Prison for Stalking, Attacking Woman with Weapon and Hydrochloric Acid After Warrant Dismissal
Video News
Video News
Video News