World Church · October 9, 2026
Two Korean megachurches report suspected data breach affecting 850,000 members
Yoido Full Gospel Church and Sarang Church in Seoul, South Korea, have confirmed that they are under investigation following a suspected cyberattack that may have exposed the personal information of their congregants. The breach was identified by a security firm and has prompted immediate containment measures and public apologies from church leadership.
Yoido Full Gospel Church, widely recognized as the largest church in the world, announced on October 7 that the personal details of 850,000 members, including names and dates of birth, may have been compromised. The church stated that an investigation into seven suspected leaked documents found that six contained no personal data, but one document detailing the history of member information changes included the sensitive data of the 850,000 individuals. This specific document also contained records of 2,629 changes to resident registration numbers, 3,964 changes to telephone numbers, and 7,202 changes to addresses. The church clarified that while records related to past donations were also leaked, they did not include personal identifying information.
The incident was first brought to the church's attention on October 6 at 3:00 p.m. when the Korea Internet & Security Agency notified Yoido Full Gospel Church that its information systems were suspected of being compromised. The church subsequently began an investigation with external specialists. By 1:00 a.m. on October 7, the church had taken measures to secure its systems, including blocking external connections and changing server passwords. The church has stated that it has notified the affected members of the suspected breach. Senior Pastor Lee Yong-hoon issued a public apology, expressing a sense of heavy responsibility for the concern caused to the congregation. He indicated that the church would cooperate with relevant authorities and thoroughly review its information protection systems.
Sarang Church also confirmed that it had become aware of a situation where personal information might have been leaked. The church established an emergency response team and reported the incident to the relevant authorities. It is currently taking measures to prevent the expansion of the damage. The security firm Oasis Security identified the breach after analyzing an attacker's server located overseas. The analysis revealed a large volume of member information from both churches that was allegedly stolen in August. The firm reported that the leaked data from Yoido Full Gospel Church included 330,000 donation records, 960,000 member information files, and 68,000 electronic approval documents. For Sarang Church, the data reportedly included information on 89,000 members and 286 staff members, including senior pastors.
Oasis Security's analysis suggests that the attackers used a malicious program known as a web shell to infiltrate the servers of Yoido Full Gospel Church. In the case of Sarang Church, the attackers are believed to have accessed the servers using account information that had been obtained in advance. The security firm noted that this attack method differs from recent hacking incidents in the financial sector that were suspected of using artificial intelligence. Consequently, the firm assessed that the possibility of the same attacker being responsible for both the financial sector incidents and these church breaches is low. The discovery of the attacker's server was made in September while the firm was tracking multiple internet protocol addresses suspected of being used in the hacking.