cd /news/ai-agents/hackers-who-may-have-used-ai-agents-… · home › topics › ai-agents › article
[ARTICLE · art-146663] src=madrobot.blog ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Hackers who may have used AI agents stole data on nearly a million members of Seoul’s biggest church

Yoido Full Gospel Church and SaRang Church in Seoul confirmed on Wednesday they are investigating suspected data breaches after security firm Oasis Security recovered attack tools and logs from an overseas attacker's server last month, according to the Korea JoongAng Daily. The server held about 330,000 donation records from Yoido Full Gospel Church taken in August, details of about 960,000 church members updated over the past two years, about 68,000 internal approval documents, and 14,706 internal messaging records; Yoido Full Gospel Church's own review found the names, dates of birth and other personal details of 850,000 members may have leaked, while SaRang Church data on the server included 286 records on staff and officials and information on more than 89,000 members. Oasis Security said the attacker's logs referred to a "sub-agent" and included an "attack handover report," though neither church nor Korean authorities have confirmed AI was used; the breaches follow attacks on South Korean banks including KB Kookmin, Hana and Shinhan where researchers found traces of the ARTEX hacking tool.

by read3 min views1 publishedOct 7, 2026
Hackers who may have used AI agents stole data on nearly a million members of Seoul’s biggest church
Image: Madrobot (auto-discovered)

Yoido Full Gospel Church in Seoul, lit up for Christmas in December 2016. Image: Striker9498 / Wikimedia Commons, CC0, cropped

Two of South Korea’s biggest churches say their members’ personal data may have been stolen, in the latest of a run of attacks on Korean organisations that investigators think may have used AI. Yoido Full Gospel Church, billed as the world’s largest Protestant church by membership, and SaRang Church, both in Seoul, confirmed on Wednesday that they are investigating suspected breaches.

The leaks came to light after security firm Oasis Security recovered attack tools and logs from an overseas attacker’s server last month, the Korea JoongAng Daily reports.

What was on the attacker’s server #

According to Oasis Security, the server held about 330,000 donation records from Yoido Full Gospel Church that appear to have been taken in August, along with details of about 960,000 church members updated over the past two years. It also held about 68,000 internal approval documents and 14,706 records of conversations on the church’s internal messaging system.

Yoido Full Gospel Church’s own review found that the names, dates of birth and other personal details of 850,000 members may have leaked, the Korea Herald reports. The church said it had been alerted by the Korea Internet and Security Agency (KISA) and was working with the authorities and security experts “to determine exactly what happened”.

Data from SaRang Church’s human resources system was also on the server: 286 records on staff and officials, including its senior pastor, and information on more than 89,000 members. SaRang said it had set up an emergency task force and reported the incident to the authorities.

Signs of an AI agent at work #

Oasis Security says the attacker’s logs referred to a “sub-agent”, a term used for an AI system that carries out tasks handed to it by another AI. The server also held an “attack handover report” summing up what had been taken, how the churches’ internal systems were laid out and which accounts had been compromised.

“The attacker appears to have exploited authentication and authorization vulnerabilities to expand access to major internal systems,” the firm said. Neither church nor the Korean authorities have confirmed that AI was used, and Oasis Security has not said who it thinks is behind the attack.

Part of a wider wave #

The church breaches follow attacks on South Korean banks including KB Kookmin, Hana and Shinhan, where security researchers found traces of ARTEX, a hacking tool that describes itself as an “AI autonomous penetration test console”. On Monday, South Korea’s President Lee said AI may have been used in those attacks, and police set up a dedicated team to investigate.

Churches hold a lot of sensitive information on their members, from addresses and family details to how much each person gives, which makes them an attractive target and a sensitive one to lose.

Why it matters #

If the “sub-agent” logs are what they appear to be, attackers are now handing whole intrusions to AI agents and getting a neat written report at the end. The same playbook used on Korea’s banks is now reaching organisations with far smaller security budgets, and nearly a million churchgoers may be the latest to pay for it. Sources: Korea JoongAng Daily, The Korea Herald.

── more in #ai-agents 4 stories · sorted by recency
── more on @yoido full gospel church 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hackers-who-may-have…] indexed:0 read:3min 2026-10-07 · —