Wednesday, October 7, 2026
Follow on LinkedIn

Hackers Breach Two Major South Korean Churches, Exposing Data of Over 1 Million People

Hackers breached two major South Korean churches, exposing more than one million congregant records and extensive financial and administrative data.

The investigation reveals how web shells, leaked credentials, and weak access controls opened routes into connected systems. In one case, attackers entered through a web shell planted in an enterprise resource planning, or ERP, system.

In the other, they used leaked credentials and insecure direct object reference, or IDOR, flaws in groupware and membership systems to reach sensitive records.

Analysts at OASIS identified the activity after examining files recovered from an attacker-controlled server. The evidence points to a multi-stage campaign involving database access, internal movement, and cloud staging, rather than a single malware strain.

OASIS said in a report shared with Cyber Security News (CSN) that the attackers collected records connected to congregants, donations, payroll, employee data, approval documents, chats, and identity information.

That is particularly concerning because community organizations can hold sensitive information that criminals could use for fraud or targeted scams. Unique-person totals remain unverified.

Hackers Breach Two Major South Korean Churches

Researchers collected files from an attacker server between August 28 and September 1, 2026. The U.S.-based server contained tooling, stolen data, and operator reports related to both victims.

The first intrusion involved a web shell in the church’s ERP system. Attackers reversed ERP application files, decrypted database settings, and obtained administrator access to Microsoft SQL Server.

They then used xp_cmdshell, a SQL Server feature that can launch operating-system commands, to move across linked systems.

That access opened member, accounting, access-control, library, chat, and mail databases. Attackers bypassed a database-monitoring control, recovered a MariaDB root password, and used hardcoded NAS credentials to reach backup storage.

Similar misuse has appeared in SQL Server attack investigations, where a database becomes a route to the underlying Windows host.

The collection contained about 960,000 congregant records updated in the previous two years, including names and resident registration numbers.

Exfiltrated [Victim A] dumps in [Victim A]_loot (Source - OASIS)
Exfiltrated [Victim A] dumps in [Victim A]_loot (Source – OASIS)

It also included roughly 330,000 donation records, 68,000 document-creation records, more than 14,000 chats, and 6,874 login accounts. Researchers recovered 47.3 GB across 13,939 files from a compromised MinIO bucket used to stage the data.

The second church was targeted earlier through leaked credentials, groupware, and IDOR weaknesses in EKP and SIMS services. An IDOR flaw occurs when an application accepts a user-controlled record reference but fails to confirm the requester is allowed to access it.

The issue resembles the unauthenticated API data exposure reported in another faith-related service. Using a member session, attackers viewed other users’ plaintext PINs and reset a manager-privileged account.

They accessed about 89,000 congregant records, 383 employee records, 286 human-resources entries, 96 employee photos, and approval documents. The investigation also found exposed college-ministry APIs and cloud storage configured for unrestricted read and write access.

How Defenders Can Respond

Neither intrusion was a one-step event. The first progressed from internet-facing application access to database administration, remote command execution, network storage, and off-site staging.

The second turned leaked credentials and missing authorization checks into access across groupware, SIMS, SAP, and connected services.

Organizations should remove unauthorized web shells, rotate exposed passwords and tokens, and invalidate active sessions. They should inspect ERP, database, NAS, and cloud logs for unusual access, large exports, or connections to the infrastructure listed below.

Credentials found in backups, application settings, public code, or exposed storage should be treated as compromised. Administrators should disable xp_cmdshell where it is not essential, restrict linked-server privileges, and segment database systems.

Teams should investigate suspicious command execution under SQL Server service accounts, particularly activity reaching other internal hosts. For web applications, every request must verify both identity and permission to access the requested record.

Authorization testing, least privilege, and safer password-reset functions can prevent IDOR chains like this one. Earlier IDOR vulnerability mitigation coverage stresses patching, auditing sensitive changes, and rotating service credentials.

The report warns that AI can accelerate reverse engineering, vulnerability research, lateral movement, and exfiltration. Faster attacker workflows give defenders less time to detect and contain intrusions before sensitive data leaves internal systems.

Indicators and investigation artifacts below reproduce the source values exactly. Redacted addresses are not actionable indicators, and legitimate files require contextual investigation rather than automatic blocking. No literal file-hash values were published.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IPv4 address192.3.239.164U.S.-located attacker server from which researchers collected tooling and stolen material.
Redacted network10.10.***.***/24Internal network scanned through the first church’s web shell; incomplete source value.
Redacted IPv4 address114.200.***.***Public address associated with the first church’s ERP host; incomplete source value.
Redacted domainmis.[Victim A].comFirst church’s ERP target and web-shell location; victim identity withheld.
Redacted domaingw.[Victim A].comFirst church’s groupware-related host identified during reconnaissance.
Redacted domaingw.[Victim B].orgSecond church’s EKP groupware target.
Redacted domainsims.[Victim B].orgSecond church’s SIMS service affected by authorization weaknesses.
Web-shell filenamecodex_x.aspxMalicious ERP web shell; reportedly still reachable on September 9, 2026.
File artifactlogin_results_v3.jsonRecorded 197 login attempts against South Korean churches.
Operator reportHANDOVER_REPORT.mdDocumented web-shell deployment and execution context.
Operator reportCREDENTIAL_AND_SYSTEMS.mdDocumented application reverse engineering and recovered database access.
Attack scriptws.shWrapper used to send commands through the web shell.
Attack scriptwssql.shSQL-related web-shell wrapper referenced in operator notes.
Attack scriptlq_cmd.shUsed for command execution through linked SQL servers.
Attack scriptq.shUsed alongside linked-server command execution.
Attack scriptrce.shCreated temporary remote services for SYSTEM-level execution.
Application artifactSecurity.dllLegitimate ERP library reverse engineered to recover configuration secrets.
Configuration artifactServerSetting.xmlDecrypted ERP configuration yielded database administrator access.
Database artifactglobal_priv.MADMariaDB privilege data used to recover the root password; no literal hash published.
Local administrative share\\127.0.0.1\V$Loopback SMB share used to bypass a local-volume monitoring restriction; not attacker infrastructure.
Local administrative share\\127.0.0.1\W$Additional loopback SMB share used in the monitoring bypass.
Database artifact[Victim A]_Primary.mdfLegitimate MSSQL data file identified on the accessed volume; victim name redacted.
Configuration artifactweb.configBackup configuration contained hardcoded NAS credentials.
Backup-agent artifactsystem-db.sqliteContained matching NAS access credentials.
Redacted deployment pathD:\[ERP]\[Victim A]_WKERP directory where the web shell was uploaded.
Staging directoryD:\exportLocal directory used to stage exported data before uploading it.
Redacted loot directory[Victim A]_lootAttacker-side directory containing first-church dumps, tools, and reports.
Redacted loot directorypentest/[Victim B]Attacker-side directory containing second-church collections and reports.
Exfiltration scriptsiteb_pii_full.batExported sensitive database tables, packaged them, and uploaded the archive.
Stolen-data archivesiteb_pii_full.tar.gzArchive containing administrative and personal-information exports.
Stolen-data archivelms_mis_sensitive.tar.gzArchive containing 75 sensitive tables from a linked system.
Attack scriptjanro_gen.pyGenerated database-export and upload commands.
Attack scriptjanro_full2.batBatch file performing database exports, archive creation, and uploads.
Attack scriptjanro_push2.pyTransferred the generated batch file through the web shell.
Stolen-data archivejanro_church_dbs.tar.gzArchive of church-related database exports.
Stolen-data archivekis_erp_full.tar.gzArchive of ERP database exports.
Retrieval scriptcloud_pull.pyDownloaded staged MinIO objects onto the attacker server.
Retrieval logcloud_pull.logRecorded 69 retrieved files and 37 skipped objects.
Storage bucketa-bucketMinIO bucket referenced in the stolen-data upload workflow.
Stolen-data filexclickr31_user.tsvExport containing 6,874 login accounts.
Photo filename patternSDNO.jpgLegitimate photo naming pattern in the accessed resident-registration photo store.
Redacted credential fileresult_.[Victim B].org_20260525_215444.xlsxSpreadsheet containing previously leaked credentials by subdomain.
Stolen-data filegroupware_data.jsonRecovered employee and organizational information.
Stolen-data filegroupware_full.jsonAdditional recovered groupware employee information.
Stolen-data filesims_members_all.jsonSIMS membership export referenced in the recovered collection.
Stolen-data filesims_special_accounts.jsonContained 1,419 sensitive account records.
Stolen-data filename patternemployees_*.jsonEmployee JSON exports found in the attacker directory.
Stolen-data filesap_hr_employees.jsonSAP human-resources employee export.
Stolen-data fileunashamed_univgroupinfo.jsonContained eight college-ministry records with personal and bank-account fields.
Execution artifactcmd.exeLegitimate Windows command interpreter invoked through the web shell; suspicious only in context.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
0-Hour Cyber Security Alerts!
Get the latest Cyber security News sent directly to your inbox.

Cyber Security Guide

Latest Cyber News

Expert Talks