Yoido Full Gospel Church in Seoul, lit up for Christmas in December 2016. Image: Striker9498 / Wikimedia Commons, CC0, cropped
Two of South Korea’s biggest churches say their members’ personal data may have been stolen, in the latest of a run of attacks on Korean organisations that investigators think may have used AI. Yoido Full Gospel Church, billed as the world’s largest Protestant church by membership, and SaRang Church, both in Seoul, confirmed on Wednesday that they are investigating suspected breaches.
The leaks came to light after security firm Oasis Security recovered attack tools and logs from an overseas attacker’s server last month, the Korea JoongAng Daily reports.
What was on the attacker’s server #
According to Oasis Security, the server held about 330,000 donation records from Yoido Full Gospel Church that appear to have been taken in August, along with details of about 960,000 church members updated over the past two years. It also held about 68,000 internal approval documents and 14,706 records of conversations on the church’s internal messaging system.
Yoido Full Gospel Church’s own review found that the names, dates of birth and other personal details of 850,000 members may have leaked, the Korea Herald reports. The church said it had been alerted by the Korea Internet and Security Agency (KISA) and was working with the authorities and security experts “to determine exactly what happened”.
Data from SaRang Church’s human resources system was also on the server: 286 records on staff and officials, including its senior pastor, and information on more than 89,000 members. SaRang said it had set up an emergency task force and reported the incident to the authorities.
Signs of an AI agent at work #
Oasis Security says the attacker’s logs referred to a “sub-agent”, a term used for an AI system that carries out tasks handed to it by another AI. The server also held an “attack handover report” summing up what had been taken, how the churches’ internal systems were laid out and which accounts had been compromised.
“The attacker appears to have exploited authentication and authorization vulnerabilities to expand access to major internal systems,” the firm said. Neither church nor the Korean authorities have confirmed that AI was used, and Oasis Security has not said who it thinks is behind the attack.
Part of a wider wave #
The church breaches follow attacks on South Korean banks including KB Kookmin, Hana and Shinhan, where security researchers found traces of ARTEX, a hacking tool that describes itself as an “AI autonomous penetration test console”. On Monday, South Korea’s President Lee said AI may have been used in those attacks, and police set up a dedicated team to investigate.
Churches hold a lot of sensitive information on their members, from addresses and family details to how much each person gives, which makes them an attractive target and a sensitive one to lose.
Why it matters #
If the “sub-agent” logs are what they appear to be, attackers are now handing whole intrusions to AI agents and getting a neat written report at the end. The same playbook used on Korea’s banks is now reaching organisations with far smaller security budgets, and nearly a million churchgoers may be the latest to pay for it. Sources: Korea JoongAng Daily, The Korea Herald.