INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Religious Institutions Confirm Cyber Attack Exposes Large-Scale Personal Information

| 2026-10-06 21:43 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A stolen MinIO account from a US-based religious platform was reused for domestic attacks in South Korea on October 6, 2026. The attacker secured the 'sysadmin' privileges of an MSSQL database and accessed internal systems, including ERP servers, groupware, NAS file servers, and internal messenger conversation records. Approximately three hundred thirty thousand cases of donor information, nine hundred sixty thousand resident registration numbers, sixty-eight thousand eight hundred electronic documents, fourteen thousand seven hundred six internal messenger conversation records, and forty-seven point three gigabytes of data were leaked externally. The attackers used webshells and vulnerabilities in authentication and authorization to gain access, then expanded their infiltration range by moving within the institution after initial access, resulting in an incremental expansion of the attack range.
Technical Mitigations AI-generated
• Patch the MSSQL database to secure 'sysadmin' privileges and prevent webshell-based ERP infiltration. • Regularly monitor for Insecure Direct Object Reference (IDOR) vulnerabilities in authentication and authorization systems, as well as groupware servers. • Implement data encryption on internal NAS and file servers to protect sensitive information from unauthorized access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/10/06
Attackers reused a stolen MinIO account from a US-based religious platform to access and leak large-scale personal information of members at two domestic Korean religious institutions.
organisation ERP
organisation Oasis Security
organisation Webshell
organisation Orasis Security
organisation NAS
organisation SMB
organisation SIMS
organisation SSO
organisation SAP
victims 286 employee information
Tactical Metrics
Metrics
victims
286
Employee Information