Video
[Anchor]
As the fallout from recent hacking incidents continues to grow, suspected cyberattacks have hit two major domestic churches. It appears that not only personal information of church members, but also sensitive details such as donation records, have been compromised. There are also signs that AI was utilized in these latest attacks.
We will start with an exclusive report by reporter Hong Yeongjae, followed by a more detailed discussion.
[Reporter]
Last month, while tracking multiple IP addresses suspected of being used in cyberattacks, a domestic security firm discovered an attacker's server containing massive amounts of personal information and hacking logs.
The personal data on the server originated from the integrated information system of Yoido Full Gospel Church in Seoul, which has 500,000 registered members—the largest congregation in the country.
Recorded as having been stolen in August, the data included up to two years of recent updates for 960,000 names, addresses, and phone numbers of church members, as well as sensitive details such as donation records dating from 1993 to 2019.
[Kim Geun-yong / CEO, Oasis Security: mis.fgtv.com with the code 'X' at the end is the web shell path where the hacker already succeeded in the attack. A church in our country was attacked, and the files leaked out like this.]
Hacking materials targeting Sarang Community Church in Seocho-gu, Seoul, were also discovered.
Similarly, in August, massive amounts of data were extracted from the church's personnel information system, including the names, addresses, and phone numbers of 286 staff members—including the senior pastor—and 89,000 church members.
There were also traces suspected of utilizing AI during the hacking process.
The logs detailing the attack process featured the expression "sub-agent," meaning an AI that performs commands, and an "attack handover report" was found on the server summarizing the hacking results, internal system structures, and account information.
[Nam Kyeong-heon / Director, Oasis Security: The contents analyzed by AI were documented very well so that humans could understand them, and a massive amount of data was analyzed, with hundreds of such documents.]
The security firm reported the signs of the hacking incident to security authorities last month, and the Korea Internet & Security Agency recently notified the two churches of the fact.
Full Gospel Church and Sarang Community Church stated that they would ascertain the facts and implement security measures to prevent further damage.
(Photo: Shin Jin-soo, Bae Moon-san, Kang Dong-chul | Video Editing: Yoon Tae-ho)
---
[Anchor]
Economic Desk reporter Hong Yeongjae is here in the studio.
Q. An "AI hacker" again?
[Hong Yeongjae: As I just reported from the article, hundreds of attack handover reports were found. The volume was vast, and the format was consistent. The security industry stated that hackers using AI recently often instruct AI to write reports in this format to receive results. Traces of using an AI tool called Artex were found in recent financial sector hacking logs. Judging by the report structure and format, it is estimated that a different low-cost AI model was used for this church hacking. There is no overlap with the IP addresses used in the financial sector hacking, so while the timing is similar, they appear to be different groups.]
Q. Did they attack other churches as well?
[Hong Yeongjae: Analyzing the files left on the attacker's server, records of 197 login attempts targeting domestic churches and denominations were found. So far, actual intrusion and information leakage have only been confirmed at the two locations, Yoido Full Gospel Church and Sarang Community Church. The security firm that confirmed the hacking is still conducting additional analysis on whether other churches were successfully hacked and whether it actually led to personal information leaks. In the case of churches or religious organizations, their professional security personnel or investment levels are relatively lower compared to regular companies, raising the possibility that attackers targeted these vulnerabilities.]
Q. Possibility of additional damage to church members?
[Hong Yeongjae: Since the victims are church members, the possibility of phishing scams mentioning church officials or donation details cannot be ruled out. In this case, although the Korea Internet & Security Agency notified the churches of the damage, religious organizations are for non-profit purposes and thus do not fall under providers of information and communications services, making them exempt from mandatory reporting of cyber infringement incidents. However, as in this case, large religious institutions hold sensitive information on hundreds of thousands of people, meaning that a hacking incident can cause damage comparable to that of a large corporation. Evaluations suggest that they are placed in a blind spot for cybersecurity management handling personal information.]