Yoido Full Gospel Church says personal information belonging to approximately 850,000 members may have been exposed in a data breach, including names and dates of birth, with smaller subsets of records containing South Korean resident registration numbers, addresses and phone numbers.
The Seoul-based church disclosed the findings on Oct. 7 after the Korea Internet & Security Agency alerted it to signs of a compromise the previous day. An investigation subsequently identified a dataset containing years of changes to member information that was suspected of being taken by an attacker.
The breach is also part of a wider investigation involving SaRang Church, another major congregation in Seoul, where researchers reportedly discovered evidence of a separate compromise.
While the exposure of member information is the primary concern, researchers examining the incidents also found evidence suggesting the attackers may have used artificial intelligence tools during parts of their operations.
850,000 member records potentially exposed
Yoido Full Gospel Church launched an emergency security review after receiving the KISA notification and brought in outside security specialists to determine what information may have been compromised.
The church said investigators identified 7 sets of data suspected of being taken during the intrusion. Six did not contain personally identifiable information, according to the church.
The remaining dataset contained a history of changes to information associated with approximately 850,000 church members. The records included names and dates of birth along with information showing changes made to individual member profiles.
A smaller portion contained substantially more sensitive information. The church identified 2,629 records involving changes to South Korean resident registration numbers, 3,964 involving phone number changes and 7,202 involving address changes.
It is not clear from the church’s disclosure whether those figures represent unique individuals or individual records, meaning the number of members whose more sensitive information was affected could differ.
The church also examined historical donation information suspected of being taken. It said those records contained transaction numbers, donation amounts and related information but did not contain names or other details that could identify individual donors.
The findings narrow the scope of the breach compared with earlier concerns that a broader collection of membership and donation information may have been compromised.
Researchers uncovered the stolen data
The potential breach was discovered after cybersecurity researchers investigating infrastructure associated with an overseas attacker found information linked to Yoido Full Gospel Church and SaRang Church.
The material reportedly included stolen information, compromised account data and records documenting attack activity.
Researchers reported their findings to South Korean authorities, leading KISA to alert the affected organizations and triggering investigations into the extent of the compromises.
Evidence gathered during the investigation indicated that attackers had reached internal systems belonging to both churches.
SaRang Church has since established an emergency response team and reported the suspected breach to relevant authorities. It continues to investigate what systems and information were affected.
Researchers reportedly discovered information associated with tens of thousands of SaRang Church accounts, although the church has not publicly confirmed a final number of affected individuals.
Exposed data could enable targeted scams
The information potentially exposed at Yoido Full Gospel Church creates risks beyond conventional spam.
Names combined with dates of birth, addresses and phone numbers could allow attackers to construct convincing phishing and impersonation attempts. Knowledge that a person belongs to a specific religious organization could make those messages significantly more targeted.
Attackers could, for example, impersonate church personnel or reference legitimate church activities when contacting affected members. The contextual information contained in the compromised records could make fraudulent communications appear more credible.
The 2,629 records involving changes to South Korean resident registration numbers are particularly sensitive because the identifiers are widely used for identity verification and can create longer-term identity theft risks if compromised.
Yoido Full Gospel Church said it has begun notifying affected members in accordance with South Korean requirements.
Church blocks access and resets credentials
The church said it deleted malicious files discovered during the investigation, blocked external access to affected systems and changed passwords for servers and related accounts.
Additional password changes are being implemented for users, while the church plans to replace its existing firewall and conduct a broader vulnerability assessment with outside security companies.
Senior Pastor Lee Young-hoon apologized to members and said the church would cooperate with authorities while strengthening its information security controls.
Investigators are still working to determine the complete intrusion path and whether additional systems or information were accessed.
Attack records show signs of possible AI use
The investigation has also produced evidence that researchers believe could indicate the attackers incorporated AI tools into parts of their workflow.
Researchers reportedly found attack records containing references to “sub-agents,” terminology commonly associated with AI systems that divide larger tasks among specialized agents.
Infrastructure examined during the investigation also reportedly contained extensive and highly structured reports documenting attack results, compromised accounts and internal system information.
The evidence does not establish that an autonomous AI system carried out the breaches. Instead, it suggests the attackers may have used AI-assisted tools for tasks such as analyzing stolen information, documenting compromised systems or coordinating parts of the intrusion.
No specific AI platform has been confirmed as having been used in the attacks.
Neither the affected churches nor South Korean authorities have publicly attributed the breaches to a known threat actor.
For Yoido Full Gospel Church, the immediate concern remains the potentially exposed information belonging to approximately 850,000 members and determining precisely what information left its systems.
The investigation into both church breaches remains ongoing.












