← Yoido Full Gospel Church

2026 Yoido Full Gospel Church — member-info change history; ~850k names/DOBs

2026 850.0K records affected Share on X

Data compromised

Member information change history for ~850,000 people: names, dates of birth, change details including 2,629 resident-registration-number changes, 3,964 phone changes, 7,202 address changes. Six other suspected datasets (parish transfers, titles, baptism) without PII per church. Donation ledgers 1993–2019: amounts/vouchers without names.

Technical writeup

Verified church statement — Yoido Full Gospel Church (Seoul) said October 7, 2026 that after KISA notified it at about 3:00 p.m. October 6 of a suspected information-system breach, emergency review with an external security firm found that one of seven suspected datasets — member information change histories — contained personal data for approximately 850,000 congregants (names, dates of birth, change details), including subsets with resident registration number, phone, and address change records. Six other datasets lacked PII. Past donation materials reportedly lacked member names. Church blocked external access and changed server passwords around 1:00 a.m. October 7, is notifying members, and is considering a police report. Korea Herald/SBS cite Oasis Security finding church data on an external server with webshell evidence amid a broader Korea cyber wave; treat actor tooling details as press-reported.

Root cause

Suspected cyberattack on church information systems (KISA notice Oct 6); webshell activity reported by Oasis Security via press

References