Yoido Full Gospel Church in Seoul announced that personal data associated with 850,000 members may have been compromised. The breach reportedly exposed names, birth dates, and a log of changes to resident registration numbers, phone numbers, and addresses. Specifically, the church identified 2,629 changes to resident registration numbers, 3,964 changes to phone numbers, and 7,202 address updates within the stolen files. South Korea’s internet security agency, KISA, flagged the suspected intrusion on Tuesday afternoon, prompting the church to block external access, change server passwords, and begin notifying affected individuals.

Security firm Oasis Security discovered the data on an overseas server alongside attack logs that referenced AI sub-agents and appeared machine-generated. A second institution, Sarang Church, also reported a breach affecting approximately 89,000 member records and 286 employee records, including those of the senior pastor. These incidents coincide with President Lee Jae Myung’s confirmation that AI is believed to have been used in recent hacks targeting South Korean commercial banks, such as Shinhan Bank, which exposed details for about 25,000 customers. While the exact role of AI in the church breaches remains under investigation, Yoido plans to replace its firewall and engage security firms to identify further vulnerabilities.