Oasis Security: attackers broke into two of South Korea's largest churches through an ERP web shell and leaked credentials plus IDOR flaws, taking about 960,000 and 89,000 congregant records along with donation, payroll and HR data
Oasis Security has analysed files recovered from an attacker-controlled, US-based server used against two of South Korea's largest churches, which it does not name. Researchers collected the files between 28 August and 1 September 2026; Cyber Security News reported the findings on 7 October. At the first church, a web shell on the enterprise resource planning (ERP) system let the attackers decrypt database settings, gain administrator access to Microsoft SQL Server and use xp_cmdshell to run commands and move to linked systems, opening member, accounting, access-control, library, chat and mail databases; they also got past a database-monitoring control, recovered a MariaDB root password and used hardcoded NAS credentials to reach backup storage. That haul held about 960,000 congregant records updated in the past two years, including names and resident registration numbers, about 330,000 donation records, 68,000 document records, more than 14,000 chats and 6,874 login accounts; 47.3 GB in 13,939 files was found staged in a compromised MinIO bucket. The second church was entered earlier with leaked credentials and insecure direct object reference (IDOR) flaws in its groupware and membership (SIMS) systems: from a normal member session the attackers could see other users' plaintext PINs and reset a manager-level account, then reached SAP and took about 89,000 congregant records, 383 employee records and approval documents. Oasis says third-party transfers mean the recovered volume is a lower bound and unique-person totals are unverified. Primary: Oasis Security; wire: Cyber Security News.
- Product
- Church ERP, groupware, membership (SIMS) and SAP systems; Microsoft SQL Server, MariaDB, NAS and MinIO storage
- Versions
- n/a
- Exploited in Australia?
- unknown
- Patch to
- Hunt for and remove web shells on internet-facing business apps, turn off xp_cmdshell where it is not needed and limit linked-server rights, take hardcoded credentials out of app settings and backups and rotate any found, and test every record lookup for authorisation so one logged-in user cannot read or reset another's account. Community and not-for-profit organisations holding member and donation data should treat these as the same risks a business faces.
Primary: Oasis Security — Analysis of cyber intrusions targeting major religious organisations in South Korea · Vendor: Cyber Security News — Hackers breach two major South Korean churches, exposing data of over 1 million people (7 Oct 2026)
