Security firm Oasis Security said on Oct. 6 that analysis of an overseas attacker's server showed congregant data, donation records and internal documents leaked from two large churches.
Two large Korean churches were hit by cyberattacks from overseas, and congregants' personal information, donation and accounting data and internal documents were confirmed leaked. Cybersecurity firm Oasis Security made the announcement on Oct. 6 after analyzing the attacker's server. The churches were identified only as Church A and Church B.
광고 문의 · 300×250From Church A, about 330,000 donation records, about 960,000 records of congregant information from the past two years, about 68,000 electronic approval documents and 14,706 internal messenger conversations, 47.3 GB in all, were taken. At Church B, information on 89,000 congregants and 286 records on staff were found to have leaked.
Entry routes: a web shell and stolen credentials
The methods differed. At Church A, the attacker used a malicious program called a web shell to break into the enterprise resource planning (ERP) server, gained administrator rights and spread to other internal systems. At Church B, the attacker used credentials obtained in advance to reach the groupware, gained administrator rights and entered the ERP through the single sign-on function.
Security experts note that religious bodies are easy targets because they keep sensitive information such as congregation rolls and donation histories in one place while investing relatively little in security. The cases show that when basics such as account management and server vulnerability checks slip, even large organizations struggle to avoid damage.
What users can do
No official response from police or the Korea Internet & Security Agency was confirmed in this report. Congregants of the churches concerned should change passwords on any other site where they reuse the same one and be wary of texts and calls impersonating the church or acquaintances. Foreign residents and ethnic Chinese families in Korea may also want to check how personal data given to religious and community groups is managed.