The breach
Real talk: the vibes are off for the Yoido Full Gospel Church in Seoul. The church, which once held the Guinness title for the world’s largest congregation, confirmed Wednesday that a massive data breach may have compromised the info of 850,000 members.
South Korea’s internet security agency, KISA, flagged the issue on Tuesday. The church’s own audit discovered the exposed files included names, birth dates, and a log showing thousands of changes to registration numbers, phone digits, and home addresses. It’s giving major security failure, and the church is currently scrambling to patch its firewall and bring in external pros to hunt for more vulnerabilities.
AI in the driver’s seat?
The plot thickens because cybersecurity firm Oasis Security tracked this data to an overseas server that also contained info from a second Seoul institution, Sarang Church. That breach affected around 89,000 member records and almost 300 employee files. Oasis found evidence suggesting the hackers utilized "AI sub-agents"—helper programs designed to automate specific tasks—to pull off the heist. These machine-written attack logs suggest the intruders might be scaling their operations using LLMs, which is a major L for privacy.
A wider trend?
This isn't just a church problem. President Lee Jae Myung confirmed on Tuesday that AI is likely behind recent raids on South Korean banks. Shinhan Bank was hit recently, with hackers lifting income data and borrowing limits for about 25,000 customers. Financial regulators have already launched an emergency inspection.
If you’re holding bags of personal data in centralized databases, this is a reminder that the threat landscape is evolving fast. Stay vigilant, keep your security tight, and remember that no platform is truly unhackable. This is for information only and definitely not financial or security advice—stay safe out there.
Why it matters
This incident highlights a scary new reality where attackers use automated AI "sub-agents" to conduct sophisticated, large-scale data harvesting. When massive databases of personal, sensitive info are left exposed, AI can scrape that data in seconds, making breaches significantly more efficient for bad actors.





