Security firm finds church-related data on overseas attacker server
Personal details, donation records from Yoido Full Gospel Church, Sarang Church discovered
Two of South Korea's largest churches have been exposed to cyberattacks, amid a string of recent hacking incidents targeting the country's financial sector.
The breaches may have resulted in the leak of nearly 1 million records containing church members' personal information and donation histories.
Cybersecurity intelligence firm Oasis Security analyzed attack tools, logs, data and account credentials obtained from an overseas attacker's server and found large volumes of member data linked to Yoido Full Gospel Church and Sarang Church in Seoul, according to Yonhap on Wednesday.
Oasis Security said both churches showed signs that attackers had moved laterally from initially compromised systems into other internal systems.
Church-related data was found on the overseas attacker's server, suggesting the files had been transmitted to an external server, the firm said.
At Yoido Full Gospel Church, attackers are believed to have used a webshell — a type of malicious program — to infiltrate the church's enterprise resource planning (ERP) server and gain administrator-level access to the database it operates.
The overseas attacker's server contained approximately 330,000 donation records and about 960,000 member records updated over the past two years, both believed to be linked to the church, the firm said.
It added that roughly 68,000 electronic approval documents and 14,706 internal messenger chat logs were also found, totaling about 47.3 gigabytes of data.
At Sarang Church, attackers are believed to have used previously obtained account credentials to access the church's groupware server. They then accessed other users' information to secure administrator-level accounts and used a single sign-on function to gain entry to the ERP system as well, the firm said.
The overseas attacker's server also contained data believed to be linked to Sarang Church, including personal information on 89,000 members and 286 staff records, the firm said.
Oasis Security said the administrator account of an external storage server connected to a breach of a US religious content and streaming service was also found to have been used to store and transmit data related to the Korean churches.
"There is a need to examine how core business systems — such as HR and accounting systems, groupware and databases — are interconnected, and to review the authentication and authorization frameworks in place," Oasis Security said.
Yoido Full Gospel Church said it had recently been notified by the Korea Internet & Security Agency of suspected personal data leaks involving its information systems, and that it was working with relevant authorities and security experts to verify the facts. "We will do our utmost to prevent recurrence through additional damage prevention measures and a comprehensive review and reinforcement of our information security framework," it added.
Sarang Church said it had discovered signs of a possible personal data breach, formed an emergency task force and reported the matter to the relevant authorities, and was taking steps to determine the cause and prevent further damage.
pink@heraldcorp.com
