South Korea’s largest congregation, Yoido Full Gospel Church, disclosed that information belonging to approximately 850,000 members may have been accessed. The stolen files contained names, dates of birth and a detailed audit of modifications made to residents’ registration numbers, phone contacts and home addresses. A second megachurch, Sarang Church, reported a smaller but still significant loss, affecting around 89,000 members and 286 staff members, including the senior pastor.
Use of AI sub-agents in the attack
Cyber-security firm Oasis Security, while tracing the origin of the intrusion, discovered the compromised data on a foreign server together with logs that referenced “AI sub-agents.” These are auxiliary programs launched by a primary artificial-intelligence model to handle discrete portions of a larger task. The accompanying attack reports appeared to be generated by a machine, although the exact contribution of AI to the compromise remains under investigation.
Immediate response and mitigation steps
Following notification from the Korean Internet Security Agency (KISA), Yoido Full Gospel Church blocked all external connections to its network, reset server passwords and engaged additional security consultants to locate further vulnerabilities. The church also announced plans to replace its firewall and to conduct a thorough forensic review. Sarang Church formed an emergency task force, reported the incident to authorities and began informing affected individuals.
Wider context of AI-enabled cyber threats in South Korea
The incidents arrive amid a broader pattern of AI-linked intrusions targeting South Korean institutions, including recent breaches at major banks such as Shinhan. Authorities have opened emergency on-site inspections of the financial sector, underscoring growing concerns about how generative-AI tools may be weaponized for large-scale data theft.
Why it matters
The exploitation of AI to automate and scale data exfiltration marks a shift in the threat landscape, demonstrating that even organizations with massive user bases are vulnerable to sophisticated, algorithm-driven attacks. The breach highlights the urgency for religious and other non-profit entities to reassess their cyber-defense postures, invest in AI-aware security solutions and maintain transparent communication with their constituencies when personal information is at risk.




