cd /news/ai-safety/hackers-used-ai-agents-to-raid-a-meg… · home › topics › ai-safety › article
[ARTICLE · art-147085] src=decrypt.co ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Hackers Used AI Agents to Raid a Megachurch's Database, Exposing 850,000 Members

Yoido Full Gospel Church in Seoul said Wednesday that personal data tied to 850,000 members may have been stolen, after South Korea's internet security agency KISA flagged the suspected breach on Tuesday afternoon. Oasis Security found the data on an overseas server alongside attack logs referencing AI sub-agents and machine-written attack reports, though the exact role of AI remains unclear; Sarang Church separately lost about 89,000 member records and 286 employee records, and President Lee Jae Myung confirmed AI is believed to have been used in recent hacks on South Korean commercial banks including Shinhan Bank, which exposed data on about 25,000 customers.

by read2 min views3 publishedOct 7, 2026
Hackers Used AI Agents to Raid a Megachurch's Database, Exposing 850,000 Members
Image: Decrypt (auto-discovered)

In brief

  • Yoido Full Gospel Church in Seoul said Wednesday that data tied to 850,000 members may have been compromised, including names, birth dates and a log of changes to ID numbers, phone numbers and addresses.
  • Security firm Oasis Security found the data on an overseas server alongside attack logs that referenced AI sub-agents and looked machine-generated, though AI's exact role is unclear.
  • Sarang Church, a second Seoul megachurch, reportedly lost records on about 89,000 members and 286 employees, as South Korea also probes suspected AI-assisted hacks at banks including Shinhan.

Yoido Full Gospel Church, the Seoul megachurch Guinness once recognized as the largest congregation in the world, said Wednesday that personal data tied to 850,000 members may have been stolen.

The church's initial review found names and dates of birth, plus a log of changes members had made to their records. "The file contained 2,629 changes to resident registration numbers, 3,964 changes to phone numbers and 7,202 changes to addresses," the church said in a statement.

South Korea's internet security agency, KISA, flagged the suspected breach to the church on Tuesday afternoon. The church has since blocked outside access to its systems, changed its server passwords and begun notifying members.

Oasis Security, a cybersecurity company, found the data on an overseas server that also held attack logs and account details linked to Yoido and a second Seoul megachurch, Sarang Church. The firm came across it in September while tracing internet addresses tied to suspected attacks.

Sarang's haul is smaller: about 89,000 member records and 286 employee records, including the senior pastor's. The logs suggest that data was stolen in August, and the church has formed an emergency task force and reported the incident to authorities.

Oasis said the attack records show activity of AI sub-agents, meaning helper programs that an AI model launches to handle separate chunks of a job, along with long attack reports that look machine-written. The churches are still working out how the intruders got in, and AI's role remains unclear.

President Lee Jae Myung confirmed Tuesday that AI is believed to have been used in recent hacks on South Korean commercial banks. Shinhan Bank's breach exposed names, phone numbers, annual income and borrowing limits for about 25,000 customers, according to local news reports, and the financial regulator opened an emergency on-site inspection.

Yoido Full Gospel Church said it plans to replace its firewall, the filter that blocks unwanted traffic into a network, and bring in security firms to hunt for other weaknesses while it notifies the 850,000 members whose data may be affected.

── more in #ai-safety 4 stories · sorted by recency
── more on @yoido full gospel church 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hackers-used-ai-agen…] indexed:0 read:2min 2026-10-07 · —