Yoido Full Gospel Church, South Korea's largest church, said Wednesday that an internal analysis following a confirmed cyberattack suggests the names and dates of birth of approximately 850,000 congregants may have been leaked.
The church said in a press release that it launched an emergency security review immediately after the Korea Internet & Security Agency (KISA) notified it Tuesday afternoon at 3 p.m. of a suspected breach of its information systems. It said it then worked with external cybersecurity firms to analyze the suspected leaked data and system access logs.
Of the seven files suspected of having been leaked, six — including records of parish transfers, appointment histories and baptism records — contained no personal information, the church said. One file, a log of changes to congregant information, was found to contain some personal data.
That file held the names and dates of birth of all 850,000 congregants, along with records of changes made to their information. It also included 2,629 entries showing changes to resident registration numbers, 3,964 entries showing phone number changes and 7,202 entries showing address changes, the church said.
Among the leaked files, past offering records contained only voucher numbers, amounts and transaction details, with no personal information including names, it added.
The church said it was notifying affected congregants of the breach in accordance with relevant laws and procedures, and that it had taken additional security measures early Wednesday morning, including blocking external access and changing server passwords.
It also plans to replace its existing firewall and keep it up to date, and to conduct a vulnerability analysis and further security reinforcement work with cybersecurity firms.
Senior Pastor Lee Young-hoon apologized over the incident. "The church bears the responsibility to safely manage and protect the precious personal information of our congregants," he said. "As senior pastor, I feel a profound sense of responsibility for the concern this has caused our congregation and sincerely apologize."
Lee added that the church was taking the matter seriously. "We will actively cooperate with the investigations and verification procedures of the relevant authorities, while thoroughly reinforcing our information security systems to ensure this never happens again, and will take all necessary measures," he said.
Earlier, cybersecurity firm Oasis Security said it had discovered large volumes of congregant data from two major South Korean churches on servers operated by overseas attackers. In addition to Yoido Full Gospel Church, Sarang Church in Seocho-gu, Seoul, was also found to have been hacked.
husn7@heraldcorp.com