An attacker’s server held data tied to 850,000 church members.

Another of South Korea’s largest churches, SaRang, has not said how many members are affected.

Attackers installed a web shell for administrator access at one organization and used leaked passwords and application flaws at the other.

Oasis Security did not identify the hackers or establish why the religious organizations were targeted.

Yoido Full Gospel Church is working with authorities and security specialists to determine how much was taken.

How each outlet framed it
The Record leans critical
reveals breach discovery through Oasis Security's analysis of attacker-controlled overseas server, discloses 850,000+ member records

Sources: The Record