Yoido Full Gospel Church in Seoul announced that personal data associated with 850,000 members may have been compromised. The breach reportedly exposed names, birth dates, and a log of changes to resident registration numbers, phone numbers, and addresses. Specifically, the church identified 2,629 changes to resident registration numbers, 3,964 changes to phone numbers, and 7,202 address updates within the stolen files. South Korea’s internet security agency, KISA, flagged the suspected intrusion on Tuesday afternoon, prompting the church to block external access, change server passwords, and begin notifying affected individuals.
Security firm Oasis Security discovered the data on an overseas server alongside attack logs that referenced AI sub-agents and appeared machine-generated. A second institution, Sarang Church, also reported a breach affecting approximately 89,000 member records and 286 employee records, including those of the senior pastor. These incidents coincide with President Lee Jae Myung’s confirmation that AI is believed to have been used in recent hacks targeting South Korean commercial banks, such as Shinhan Bank, which exposed details for about 25,000 customers. While the exact role of AI in the church breaches remains under investigation, Yoido plans to replace its firewall and engage security firms to identify further vulnerabilities.
The convergence of religious institutional data theft and banking sector intrusions signals a shift in threat actor methodologies, where automated tools are increasingly deployed to scale reconnaissance and exploitation across diverse sectors. The presence of AI sub-agents in attack logs suggests that adversaries are leveraging autonomous or semi-autonomous systems to execute complex tasks, potentially lowering the barrier for sophisticated cyber operations while increasing the volume of data exfiltrated. This development underscores the vulnerability of large-scale membership databases, which hold high-value personally identifiable information that can be monetized or used for social engineering campaigns against specific demographics.
Regulatory and operational responses must now account for the ambiguity surrounding AI's precise role in these breaches, as attribution challenges complicate incident response and legal accountability. The simultaneous probing of banks and megachurches indicates a coordinated or opportunistic campaign exploiting common infrastructure weaknesses, likely involving outdated firewalls or insufficient monitoring. Institutions should prioritize immediate containment measures, such as password rotation and access blocking, while engaging third-party forensic experts to determine if AI-assisted vectors were used for initial entry or lateral movement. The lack of clarity on how intruders accessed the systems highlights a critical gap in current defensive postures against adaptive, machine-driven attacks.


