Invest1 publisherNot yet confirmed elsewhere2 min readPublished
Attackers' servers held 960,000 member records from Korea's Yoido Full Gospel Church
Oasis Security says attackers' servers held about 960,000 Yoido Full Gospel Church member records with resident registration numbers. The church is still verifying, but the cache shows how much identity and donation data sits behind one administrator account at a large congregation.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Oasis also identified about 330,000 records of Yoido member offerings that were logged as stolen in August.
- The same cache held about 68,000 electronic approval documents and 14,706 internal messenger conversations, roughly 47.3 gigabytes in all.
- At Sarang Community Church, names, addresses and phone numbers for about 89,000 members turned up on the attacker's server.
- Sarang's intruder is believed to have entered groupware with credentials obtained in advance, then reached the ERP system through single sign-on.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- contradiction Defenses tuned to Korea's recent bank attacks may miss this route, because Oasis judges the church methods different and a shared attacker unlikely.
- decision Large institutions running HR, accounting, groupware and databases behind shared logins now have to choose between single sign-on convenience and limiting how far one stolen credential reaches.
- exposure If Yoido confirms the theft, its donors' giving histories sit in outside hands next to their resident registration numbers, a pairing far more sensitive than a contact list.
Divide one Yoido count by the other and the attacker's server holds roughly one offering record for every three member records, 330,000 against 960,000 [2][17]. That ratio makes Yoido's case a money breach as well as a privacy one. Sarang's files, as Oasis Security describes them, are contact details [6], plus data on 286 staff and officials including the senior pastor [7]. Add the two churches together and the member records total about 1,049,000 [18]. Yoido's figure counts records updated over two years [1], so it need not equal distinct people.
The incidents come as hacking cases mount across Korea, including in the financial sector [16]. On the type of data lost, a national ID number next to a record of money given, the church files look like a bank's. On the attacker and the method, Oasis points away from the banks [13].
Both intrusions reached the enterprise resource planning system, by different doors. At Yoido the web shell went onto the ERP server itself, and Oasis saw signs the attacker then widened access to services tied to other internal systems [5]. At Sarang the route was sideways, from groupware to the ERP through a single sign-on function [8]. Each depended on administrator-level privileges once inside [5][8]. I think the exposure for large donor-funded institutions sits in how those systems are linked, where one admin account or one login reaches the accounting data, and the bank comparison helps only on what was taken.
That view could be wrong in two directions. Yoido's review could shrink the scope. The church told Newsis it is checking the time period and scope involved, and that it is difficult to state anything definitively while the investigation is under way [11]. Or the weak point could sit outside church networks altogether. Oasis raised the possibility that credentials or infrastructure from a breach of a U.S. religious content and streaming service were used. The firm said the evidence so far is not enough to conclude the same party carried out the attacks [14].
Yoido learned of the suspected breach from the Korea Internet & Security Agency [15]. It says it will report to authorities and notify members if a breach is confirmed, and will explain what it has found at its Wednesday service [12]. Sarang has formed an emergency task force and reported the matter to the authorities [9]. Neither church has confirmed how many members were affected. The money-breach thesis fails if Yoido finds the 330,000 offering records logged as stolen in August never left its systems [3].
What to watch
- What Yoido tells members at its Wednesday service, and whether it confirms a count of affected members and offering records.
- Whether investigators tie the churches' intrusions to credentials from the breached U.S. religious content and streaming service.
- Whether other Korean religious institutions find their data on the same attacker servers Oasis analyzed.