2 South Korean megachurches probe suspected AI-linked cyberattacks

Sign up now: Get insights on Asia's fast-moving developments

Records of the alleged attacks included signs that AI tools were used during the intrusion.

Records of the alleged attacks included signs that AI tools were used during the intrusion.

PHOTO: LIANHE ZAOBAO FILE

SEOUL - Two South Korean megachurches are investigating suspected cyberattacks that may have exposed the personal data of hundreds of thousands of congregants, with evidence suggesting AI tools may have been used in the attacks, according to the churches and a cybersecurity firm.

Cybersecurity company Oasis Security found data, attack records and account information on an overseas server that contained information linked to Seoul’s Yoido Full Gospel Church and Sarang Church.

Records of the alleged attacks included signs that AI tools were used during the intrusion, such as references to “sub-agents” and extensive attack reports that appeared automated, Oasis Security said.

Yoido Full Gospel Church said on Oct 7 that initial analysis indicated data relating to 850,000 members may have been compromised.

The data included names and dates of birth with a smaller number of records containing changes to national identification numbers, addresses and telephone numbers.

The church said it was notifying affected members, blocking external access and changing server passwords.

Sarang Church, in Seoul’s Seocho district, said it had formed an emergency task force, reported the suspected incident to relevant authorities and was taking steps to determine what happened and prevent further harm.

The news follows hacking attacks against South Korean commercial banks that led to a breach of customers’ personal information.

South Korean President Lee Jae Myung said on Oct 6 that AI was believed to have been used in the cyberattacks. REUTERS

See more on