
Share
Two of Seoul's largest congregations are notifying hundreds of thousands of members after attackers, possibly aided by AI tools, breached membership systems in what looks like a widening pattern of automated financial crime in South Korea.
For most people, a church membership roll feels like one of the safer places to put your name, your birthdate, your phone number. It's not a bank account. It's not a hospital record. But that sense of safety is exactly what makes this story unsettling: two of South Korea's largest megachurches are now investigating cyberattacks that may have exposed the personal data of hundreds of thousands of congregants, and the fingerprints left behind suggest artificial intelligence may have done some of the work.
Seoul's Yoido Full Gospel Church, one of the largest Pentecostal congregations in the world, said Wednesday that initial analysis points to data on 850,000 members being compromised. Names and dates of birth were exposed, the church said, along with a smaller set of records showing changes to national identification numbers, addresses, and phone numbers. The church is now notifying affected members, blocking outside access to its systems, and resetting server passwords.
Across town, SaRang Church in Seoul's Seocho district is dealing with a related but separate problem. Cybersecurity firm Oasis Security says attackers exploited a flaw in the church's membership system that could have exposed data tied to as many as 89,580 registered user accounts. SaRang has formed an emergency task force, reported the suspected breach to authorities, and is working to determine exactly what happened and how to stop further damage.
Oasis Security said it found data, attack records, and account information tied to both churches sitting on an overseas server, a kind of digital staging ground attackers sometimes use to store what they've stolen before deciding what to do with it. What caught investigators' attention wasn't just the data itself. It was how the intrusion appeared to have been carried out.
Think of a traditional hack as a burglar picking a lock by hand: slow, deliberate, requiring real skill and time. What Oasis Security found looked more like a burglar who sent in a team of assistants to do the work simultaneously, then compiled a tidy report of everything they found. The firm said the intrusion records included references to "sub-agents," a term used in AI systems to describe smaller automated programs that handle specific tasks under the direction of a larger one. The attack reports themselves appeared extensive and automated, not the kind of manual notes a lone hacker typically leaves behind.
That distinction matters more than it might seem. AI tools can make cyberattacks faster, cheaper, and easier to scale, letting a single attacker probe for weaknesses across many systems at once rather than targeting one organization at a time. It also makes it harder for defenders to tell whether they're dealing with a sophisticated criminal operation or something closer to an experiment run by a smaller group with access to the right tools.

This isn't an isolated case. The church breaches follow closely on the heels of hacking attacks against South Korean commercial banks that led to the exposure of customers' personal information. President Lee Jae Myung said Tuesday that AI was believed to have been used in those bank attacks as well. Taken together, the pattern suggests something broader than a single opportunistic hacker: a wave of intrusions across very different kinds of institutions, financial and religious alike, with AI showing up as a common thread.
South Korea has seen explosive growth in some Pentecostal churches over recent decades, and Yoido Full Gospel Church is among the most prominent examples of that growth. Large congregations like it function less like small community chapels and more like sprawling institutions, with membership databases, financial systems, and administrative infrastructure that rival those of mid-sized corporations. That scale is part of what makes them attractive targets. A breach there doesn't affect dozens of people. It potentially affects hundreds of thousands.
For the people whose names, birthdates, and in some cases identification numbers were exposed, the risks are concrete rather than theoretical. Stolen identity information can be used to open fraudulent accounts, intercept government benefits, or build convincing phishing attempts that reference real personal details to seem trustworthy. Older congregants, who may make up a significant share of a megachurch's membership, are often disproportionately targeted by scams that exploit exactly this kind of leaked information.
Both churches are taking the standard first steps: notifying members, alerting authorities, locking down systems. Those are the right moves, but they don't undo the exposure that's already happened. Once personal data sits on an external server, as Oasis Security found it did here, there's no clean way to guarantee it hasn't already been copied, sold, or put to use elsewhere.
The use of AI in these attacks, if confirmed, points to a shift that security researchers have been warning about for a while: the tools that make automation useful for legitimate businesses can just as easily make attacks more efficient for criminals. Sub-agents that can be directed to search for vulnerabilities, compile stolen data, and generate reports don't require the same time investment that manual hacking once did. That lowers the barrier to entry for attackers and raises the stakes for any organization holding sensitive personal data, whether it's a bank, a hospital, or a church.
What makes this case worth watching closely is the breadth of targets. Banks hold financial data. Churches hold identity data tied to community and trust. If AI-assisted attacks are hitting both with similar methods, it suggests the threat isn't confined to one sector's defenses being weak. It's a tooling problem that cuts across industries, and institutions that have never thought of themselves as high-value targets may need to start thinking that way now.
Tags
Original Sources
South Korean megachurches probe suspected AI-linked cyberattacks
↗ https://www.reuters.com/legal/litigation/south-korean-megachurches-probe-suspected-ai-linked-cyberattacks-2026-10-07
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
7 October 2026
34 articles
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.