← Blog

Yoido Church Breach: 850K Members’ Names and DOBs

Share on X

Yoido Full Gospel Church — often described as the world’s largest Protestant congregation by registered membership — said on October 7, 2026 that an internal review with outside forensics found personal details for 850,000 members may have leaked, including names and dates of birth. The Korea Internet & Security Agency (KISA) flag arrived the afternoon before. English and Korean coverage: SBS, Yonhap, and The Korea Herald. Canonical record: https://breachhistory.com/yoido-full-gospel-church/yoido-full-gospel2026 (/yoido-full-gospel-church/yoido-full-gospel2026).

This is a church-confirmed Yoido Full Gospel Church data breach disclosure — not an unverified dark-web sales listing. What this is not: a statement that every one of the seven suspected datasets held PII, or that donation ledgers named givers. Most of the suspected files did not contain personal information. One did, and it was large.

How the church found out

At about 3:00 p.m. on October 6, 2026, KISA notified Yoido Full Gospel Church of suspected compromise in its information systems. The church opened an emergency security review the same day and brought in an external security specialist organization to examine suspected leak data and system access logs.

By the morning of October 7, leadership had enough confidence in the forensics to publish a press release: among seven suspected datasets, six held no personal information, while one member-information change-history file contained PII covering 850,000 people. Senior Pastor Lee Younghoon apologized publicly, accepted institutional responsibility for protecting congregants’ data, and pledged cooperation with authorities plus hardened information-protection controls.

Separately, cybersecurity firm Oasis Security told Korean media it had found large-scale church member information from two major Seoul congregations on an overseas attacker server, with evidence consistent with webshell planting and — in some reporting — AI-assisted tooling in a broader domestic attack wave. The Korea Herald placed Yoido’s confirmation alongside related reporting on Sarang Church in Seocho-gu. This article centers on Yoido’s own October 7 numbers; Sarang’s alleged employee and member counts come from secondary reporting and are not restated here as Yoido-confirmed facts.

Timeline

  1. Prior weeks (per Oasis / Korea Herald reporting) — Security researchers tracing attack infrastructure reportedly locate church-related data and webshell evidence on an external server.
  2. October 6, 2026, ~3:00 p.m. — KISA notifies Yoido Full Gospel Church of a suspected information-system breach.
  3. October 6 afternoon–evening — Emergency security check; joint analysis of suspected leak sets and access logs with external specialists.
  4. October 7, 2026, ~1:00 a.m. — Additional containment: external access blocked; server passwords changed.
  5. October 7, 2026 (daytime) — Church press release; member notifications under Korean law begin; firewall replacement and deeper vulnerability work announced; police complaint under consideration per church response planning.

What remains publicly unsettled

  • Exact initial access vector on Yoido’s own systems beyond the webshell evidence described in trade/security reporting.
  • Full duration of attacker dwell time before the KISA tip.
  • Whether every field in the 850,000-person change log left the network intact versus partial copies — the church frames the situation as a suspected leak after dataset review.
  • Criminal attribution — Korean police were already investigating a wider series of suspected AI-assisted intrusions against financial institutions in the same news cycle; any formal link to the church incidents is for investigators to establish.

What was in the seven suspected datasets

The church’s sorting is unusually specific for a crisis-day press release. Six of seven suspected leak sets contained no personal information:

  • Parish / district transfer histories
  • Title and appointment records
  • Baptism histories
  • Related operational church datasets in the same non-PII group

The seventh set — a member-information change history — is the problem file. It held:

  • Names for 850,000 individuals
  • Dates of birth
  • Change details, including counts the church published: 2,629 resident registration number (RRN) changes, 3,964 phone-number changes, and 7,202 address changes

Read the RRN line carefully. The church did not claim that 850,000 full resident registration numbers sat in the clear for every member. It said the change-history dataset included 2,629 records of RRN changes, alongside thousands of phone and address change events. For anyone in those change subsets, the exposure can still include highly sensitive Korean identity fields. For the broader 850,000, the baseline confirmed risk is name plus date of birth plus whatever change metadata surrounded their profile edits.

Donation records: amounts without names

Among materials reviewed in the leak set, past donation records covering roughly 1993–2019 contained voucher numbers, amounts, and transaction details — but not names or other personal identifiers, according to the church. That is meaningful: a decades-long giving ledger without names is less immediately useful for blackmail than a named tithe spreadsheet. It is still operational intelligence about church finance patterns if attackers retained it, and members should not assume every historical finance artifact was harmless just because the press release emphasized the missing name column.

What Yoido did after the KISA call

Containment moved overnight. By about 1:00 a.m. on October 7 the church said it had blocked external access paths and rotated server passwords. It also said it would replace existing firewalls, keep them current, and continue vulnerability analysis with specialized security firms. Member notification under applicable Korean procedures was described as already underway on release day.

Pastor Lee’s statement tracked the institutional line Korean organizations usually take after a verified breach: apologize, accept duty of care, promise cooperation with investigators, and vow system reinforcement. The practical test for members is whether notification arrives with clear field lists and concrete fraud-watch guidance — not only pastoral language.

Who is at risk

Current and former members in the 850,000 change-history cohort — anyone whose name and date of birth lived in that log should assume those fields are in hostile hands until told otherwise.

People in the RRN / phone / address change subsets — higher stakes. Resident registration numbers unlock a wide range of Korean identity and finance fraud. Phone and address changes give attackers fresh contact channels and home targeting data.

Family members sharing households — address change records and parish geography can expose relatives who never appeared as primary account holders.

Church staff and volunteers who handle member care — expect impersonation of IT helpdesks, parish offices, and “security verification” teams asking members to “confirm” identity after the news broke.

Other large Korean churches — the same reporting wave that surfaced Yoido also described Sarang Church data on the external server Oasis reviewed. Peer institutions should treat this week as a sector wake-up, not a one-congregation story.

Phishing and social-engineering patterns to expect

  • “KISA / church security confirmation” SMS asking you to tap a link and re-enter RRN, bank details, or Kakao login — Yoido’s official process will not start with a random short link in a text.
  • Fake donation-refund or offering-adjustment pages that cite the 1993–2019 finance angle and ask for account numbers “to reconcile vouchers.”
  • Pastoral deepfakes or cloned KakaoTalk profiles that greet you by name and reference your birthdate as “proof” they are legitimate.
  • Employment or volunteer onboarding lures targeting people whose title/appointment histories appeared in non-PII sets — even empty-of-PII files can teach attackers who holds which church role.

Why a church membership file is high-value to attackers

Religious organizations sit in an awkward security niche. They hold population-scale identity data, run aging custom member systems, and cultivate high-trust communication channels that members are culturally inclined to believe. A name-plus-DOB file on 850,000 people is already enough for SIM-swap research, loan-application fraud, and tailored romance or investment scams. Add even a few thousand RRN change events and the file becomes a partial national-ID harvest.

Churches also face reputational extortion paths that retailers do not. Attackers who control membership extracts can threaten selective leaks about parish transfers, discipline-adjacent metadata, or family composition inferred from address changes. Yoido’s disclosure that six datasets lacked PII reduces some of that surface — it does not erase the change-log problem.

Korea’s wider October 2026 attack climate

The Korea Herald framed the megachurch incidents against a domestic wave of suspected AI-assisted cyberattacks that also hit financial institutions, with police opening fuller investigations around the same dates. Oasis’s reporting that church data appeared on an external server with webshell evidence fits a classic post-exploitation pattern: plant a web shell, stage data, move copies offsite. Whether the same operators behind bank intrusions also hit Yoido is a question for Korean investigators, not something the church’s October 7 release settles.

For members, the campaign label matters less than the field list. If your name and birthdate are in the change history, your defensive checklist looks like any other large Korean PII breach — with extra caution around church-branded messages.

What members should do

  1. Watch for the church’s official notification and keep a copy; note which fields it says applied to you.
  2. If you ever updated RRN, phone, or address through church systems, assume those change events may be in the sensitive subset and monitor credit, telecom, and government identity services for misuse.
  3. Be skeptical of anyone who already knows your name and birthdate and asks for a second factor, bank OTP, or RRN “to secure your membership record.”
  4. Harden KakaoTalk, email, and mobile-carrier PINs — phone-change metadata in the leak set makes number-port and SMS-intercept attempts more likely.
  5. Do not pay “breach cleanup” fees to strangers who claim partnership with Yoido, KISA, or Oasis Security.
  6. Report impersonation to the church’s published security contacts and, where fraud has begun, to police — the congregation has said it is weighing formal police engagement as part of its response.
  7. Parents and caregivers — if minors or elderly relatives appear in family membership records, explain that unexpected “church IT” calls are a known risk this month.

What other faith organizations should take from this

Member databases are not low-sensitivity “directory” systems. They are identity warehouses with pastoral metadata attached. Minimum lessons from the Yoido church breach 2026 disclosure:

  • Segment change histories that include national ID fields from general parish directories.
  • Log and alert on bulk export of member tables; webshells thrive where file-write monitoring is weak.
  • Practice KISA-notification response drills so a 3 p.m. tip does not become a 24-hour scramble without counsel and forensics on retainer.
  • Publish member guidance that names the exact scam patterns tied to the incident, not only a generic apology.

Yoido’s relatively granular public inventory — seven sets, six without PII, one with 850,000 name/DOB rows and counted change events — is a model other institutions should copy when they disclose. Members can act on numbers. They cannot act on fog.

Comparing headline size to practical harm

“850,000 members” will dominate search results for the Yoido Full Gospel Church breach. The actionable split is finer. Everyone in that change log faces name-and-DOB risk. A smaller slice faces phone, address, and RRN-change exposure. Donation voucher histories from 1993–2019 appear to lack names. Baptism, title, and parish-transfer files reportedly lacked PII entirely. That stratification should shape how journalists, insurers, and members talk about “was I affected” — blanket panic and blanket dismissal are both wrong.

It also explains why the church could apologize sincerely while still telling a more precise story than “all systems, all fields, all years.” Precision does not minimize harm to the 850,000. It focuses defenses where the data actually lived.

Concrete fraud paths tied to this field mix

Name plus date of birth is the starter kit for Korean consumer fraud: loan comparison sites, secondary phone contracts, and “verify your identity to receive a church welfare stipend” pages all lean on that pair. When attackers also hold a recent phone-change or address-change event, they can time the scam to a real life transition — a move, a new handset — when victims already expect administrative hassle.

The 2,629 RRN-change records deserve a separate mental model. Even if full resident registration numbers for the entire congregation were not sitting in one flat file, change-history rows often capture before/after values or ticket notes that reconstruct identity numbers. Anyone who updated an RRN through church systems in the retained window should treat that as a potential national-ID exposure and watch government digital services, banking KYC resets, and mobile-carrier identity checks for months, not days.

Donation vouchers without names are weaker for classic blackmail, but they still help attackers invent “refund” stories with plausible amounts and date ranges. A text that says “your 2017 offering voucher needs re-validation after the cyber incident” will feel specific even when the sender never knew who you were — they only needed a realistic amount band from the anonymized ledger.

What the first 48 hours looked like from a member’s seat

Monday afternoon for many congregants was ordinary. Then KISA tipped the church at 3 p.m. Tuesday. Overnight, administrators cut external paths and rotated passwords around 1 a.m. Wednesday. By Wednesday morning, press releases and broadcast segments named the 850,000 figure. That compressed arc matters: members may hear about the Yoido Full Gospel Church data breach from television before an official SMS or letter arrives. Scammers will exploit the gap. If a message demands immediate action “before noon today” and the only proof offered is that they know your birthdate, hang up and use contact channels published on the church’s own site — not numbers embedded in the suspicious message.

Pastor Lee’s apology and pledge to cooperate with authorities set expectations that notifications and hardening work will continue. Members should still document every outreach attempt they receive this month: screenshots, sending numbers, and URLs. Those artifacts help both the church’s security vendors and police if a formal complaint proceeds.

Sarang Church and the shared reporting wave — keep the lines straight

Korean outlets bundled Yoido with Sarang Church because Oasis Security described both organizations’ data on the same external attacker infrastructure, including webshell evidence in Yoido’s case and alleged personnel/member theft figures for Sarang in August. That is relevant campaign context. It is not a license to merge the two incidents’ counts. Yoido’s confirmed public inventory is the seven-dataset review with one PII-bearing change log covering 850,000 people. Sarang’s alleged scale lives in separate reporting. If you attend Sarang, follow Sarang’s notices. If you attend Yoido, act on Yoido’s field list.

The shared AI-assisted attack narrative circulating alongside bank intrusions in early October 2026 likewise belongs in the “watch the investigation” column. Tools evolve; the member defense checklist does not depend on whether a model helped write the exploit chain.

Canonical record and sources

BreachHistory’s catalog entry lives at /yoido-full-gospel-church/yoido-full-gospel2026. Primary reporting used for this guide:

Update the catalog if Yoido publishes a narrower confirmed-exfiltration count, a technical root-cause note, or a formal police case number. Until then, the verified core is clear: after a KISA tip on October 6, South Korea’s largest church confirmed that a member change-history dataset putting names and dates of birth for 850,000 congregants at risk — with thousands of RRN, phone, and address change events inside — and moved overnight to cut external access while it notifies members and hardens the perimeter.