-
Yoido Full Gospel Church disclosed its preliminary findings on Wednesday.
-
Names, birth dates and some contact-information records may have leaked.
-
SaRang Church is investigating a separate suspected breach.
-
Investigators suspect AI involvement, but its role remains unconfirmed.
October 7, (THEWILL) – South Korea’s Yoido Full Gospel Church said on Wednesday that personal information relating to 850,000 members may have leaked, as investigations into suspected cyberattacks spread to two of Seoul’s largest congregations.
The church’s October 7 disclosure followed an examination of files and access records after the Korea Internet & Security Agency alerted it to a suspected breach the previous afternoon. Names and dates of birth were among the information identified, according to SBS’s account of the church’s statement.
Meanwhile, SaRang Church established an emergency task force and reported a suspected incident to the authorities. Cybersecurity firm Oasis Security said it had discovered information linked to both churches on an overseas server.
Wednesday’s announcement concerns the investigation’s findings. It does not mean the intrusions occurred that day.

Membership Records Under Scrutiny
Yoido said the affected material included a file recording changes to members’ information. Within it were 2,629 records of changes to national identification numbers, 3,964 to telephone numbers and 7,202 to addresses, according to the Korea Times. Those figures describe change records, not necessarily separate individuals.
The church said it was notifying affected members, blocking external access and changing server passwords. Senior Pastor Lee Young-hoon apologised.
“I feel a deep sense of responsibility for causing concern among our members as a result of this incident, and I sincerely apologise”, he said.
READ ALSO:
However, the church qualified reports about leaked donation information. It said the historical donation documents examined contained voucher numbers, amounts and transaction details without names or other personal identifiers, according to Aju Press.
Its review found personal information in one of seven suspected leaked documents. The church also said it had removed malicious code and planned further security assessments and firewall upgrades.
Suspected AI Use Remains Under Investigation
Oasis Security said attack records contained references to “sub-agents” and extensive reports that appeared automated, suggesting AI tools might have assisted the intrusions. Those observations do not establish that an AI system independently carried out the attacks.
For Nigerian churches and other organisations maintaining membership databases, the case raises a practical concern about the information collected during routine administration.
Contact details and dates of birth can remain in a system long after their original purpose has passed, while change histories can preserve information that users believe they have replaced.

Exposure could also make impersonation more convincing. A message containing someone’s correct name, congregation and personal details may appear trustworthy even when it comes from a stranger. That is a possible consequence of such a breach, not a confirmed outcome in this investigation.
Yoido is continuing to assess the extent of the exposure and notify members. SaRang’s investigation is also ongoing, with the full scope of the suspected breaches still being established.
Joy Onuorah is a business journalist and brand communications specialist covering financial markets, artificial intelligence, digital economy, and the ideas reshaping business across Africa and the global market. Beyond her reporting for TheWill, Joy uses brand strategy, storytelling, copywriting, and high-value SEO to help brands build lasting market authority.



