Security

AI Hacking Suspected Beyond the Financial Sector, Too... Large Church Faces Possible Data Leak Affecting Up to 850,000 People

IT DAILY ·

[Photo: AI-generated image]

✦ AI Summary

Yoido Full Gospel Church began an emergency security inspection after receiving notice from KISA on the 6th that there were signs of a breach of its information systems.

An outside security specialist analyzed 7 suspected leaked materials, found personal information in 1 of them, and identified the possibility that personal data belonging to up to 850,000 people, including names and dates of birth, may have been leaked.

Signs of a possible personal data leak also emerged at Sarang Church, which formed an emergency task force, and the incident was detected after materials related to Korean churches and attack records were found on an overseas attacker's server.

Following the financial sector, signs of a cyberattack suspected of involving AI have now been identified at a religious institution as well. With large religious organizations that hold vast amounts of personal data also being targeted, the need to expand security management beyond industry lines has emerged as a key issue.

Yoido Full Gospel Church said in a statement on the 7th that it had begun an emergency security inspection after receiving notice of signs of a breach of its information systems from KISA on the 6th. It then analyzed the suspected leaked materials and system access logs with an outside security specialist, and the materials analyzed totaled 7 sets. The analysis found personal information in 1 of the 7 sets, a change history for church members' information, and the church identified the possibility that personal data belonging to up to 850,000 people, including names and dates of birth, may have been leaked and began responding.

Signs of a possible personal data leak also emerged at Sarang Church. In response, Sarang Church formed an emergency task force. This once again highlighted the need to expand security management to include religious institutions.

The material was found to contain personal data on 850,000 people, and the included items were names, dates of birth, and details of information changes. Included records consisted of 2,629 resident registration number changes, 3,964 phone number changes, and 7,202 address changes. The church said the remaining 6 suspected leaked materials did not contain personal information. The church also said that the items in older offering-related records consisted of voucher numbers, amounts, and details, and that those older offering-related materials did not include personal information such as names.

Accordingly, Yoido Full Gospel Church deleted malicious files, blocked external access, and changed passwords for servers and related accounts. As a follow-up, the church is pursuing plans to notify affected congregants and inspect its systems and personal data management framework through an outside security specialist.

Sarang Church formed an emergency task force and reported the incident to the relevant authorities. It is investigating how the incident occurred and the scope of the damage.

The incident was detected when Oasis Security found materials related to Korean churches and attack records on a server used by an overseas attacker. The clues came from related materials and traces of attacks secured from the attacker's server.

According to Reuters, the records included the phrase "sub agent," and there was also an attack report that appeared to have been automated. Oasis Security said these signs support the possibility that AI tools were used.

However, at this stage, it has not been confirmed whether AI autonomously carried out the pre-attack phase. The publicly available information at this point also remains only a suspicion of AI use, and the specific role of AI and the degree of automation remain unconfirmed, making further investigation necessary.

Meanwhile, Oasis Security confirmed signs that the scope of the attack expanded from systems accessed externally at the two churches to other internal systems. Accordingly, Oasis Security pointed out the need to review the connection structure of HR, accounting systems, groupware, and databases, as well as the authentication and authorization framework.

The materials identified were not the currently used congregant registry, but rather "information change history" documents of the kind used to verify personal information. This indicates that the scope of verification may need to expand, as personal information may remain not only in the current congregant registry but also in past records of changes to contact information and addresses.

Meanwhile, a church official said the church had formed an emergency task force, completed reports to the relevant authorities, and is now determining how the incident occurred.

Source: IT DAILY · Lee Jae-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=242076

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.