Skip to content
Cybersecurity

South Korean Megachurches Investigate Suspected AI-Linked Cyberattacks

South Korean church data breach investigation raises concerns over AI-driven cyberattacks.

Two major South Korean churches are investigating suspected cyberattacks that may have exposed personal data belonging to hundreds of thousands of congregants.

The affected organisations are Seoul's Yoido Full Gospel Church and Sarang Church. Cybersecurity company Oasis Security found church-related data, account information and attack records on an overseas server, along with evidence suggesting that AI tools may have been involved in the attacks.

Yoido Full Gospel Church said its initial analysis indicated that data relating to as many as 850,000 members may have been compromised. The information included names and birth dates, while a smaller number of records contained national identification numbers, addresses and phone numbers.

Attack Records Show Signs of AI Use

Oasis Security said the attack records contained references to “sub-agents” and extensive reports that appeared to have been generated or organised automatically.

The findings suggest that AI may have been used to automate parts of the intrusion, analyse information or document the results. However, the evidence does not establish that AI independently carried out the entire attacks, and investigations into the attackers and their methods remain underway.

The incident adds to growing concerns about the use of AI tools to automate traditionally manual stages of cyberattacks, potentially allowing attackers to process large amounts of information more quickly.

Churches Take Steps to Contain the Damage

Yoido Full Gospel Church said it is notifying affected members, blocking external access and changing server passwords as it investigates the incident.

Sarang Church has established an emergency task force, reported the suspected breach to relevant authorities and is investigating the extent of the intrusion. Security teams are working to determine what information was accessed and whether additional systems were affected.

Oasis Security also identified evidence of an attack targeting Sarang Church, including account information and records associated with the intrusion. The investigation is continuing to establish the full scope of the incident.

AI-Driven Cyber Threats Gain Attention

The church investigations come shortly after a series of cyberattacks against South Korean financial institutions. South Korean President Lee Jae Myung said on October 6 that AI appeared to have been used in attacks targeting commercial banks.

The developments point to a broader cybersecurity challenge as AI tools become capable of handling reconnaissance, analysis and other tasks that previously required significant manual effort. Security teams are increasingly examining whether attackers are using AI to make existing techniques faster and more scalable.

For the two churches, however, the immediate priority remains determining exactly what was accessed, notifying affected members and preventing further compromise.