October 7, 2026, (Inside AI) — Two of South Korea's largest megachurches have launched investigations into suspected cyberattacks that may have exposed the personal data of hundreds of thousands of congregants. Evidence gathered so far suggests artificial intelligence tools played a role in the intrusions, according to the churches and a cybersecurity firm familiar with the matter.
The incidents mark a rare public acknowledgment of AI-assisted cyber operations targeting religious institutions, a sector that often holds sensitive member records but invests far less in digital defense than banks or hospitals. The churches, both based in the Seoul metropolitan area, collectively serve a membership exceeding 500,000 people, making the potential breach one of the largest data exposure events linked to faith-based organizations in the country.
Why Churches Became The Target
Megachurches in South Korea operate extensive databases that track member donations, pastoral counseling notes, family relationships, and contact details. That combination creates a valuable trove for identity thieves and extortion groups. Unlike financial firms, churches rarely employ dedicated security teams or run regular penetration tests.
The cybersecurity firm assisting the investigation, which spoke on condition of anonymity because the inquiry is ongoing, said it identified patterns consistent with AI-generated phishing lures and automated vulnerability scanning. The firm did not name the specific AI models or services involved. Inside AI could not independently verify the full scope of the breach or the exact number of affected individuals.
One church official, who spoke on condition of anonymity, said the attackers appeared to have used AI to craft Korean-language emails that mimicked internal church communications with unusual precision. The messages bypassed basic spam filters because they contained no obvious grammatical errors or suspicious links. That level of linguistic fluency represents a shift from earlier generations of phishing attacks, which often relied on awkward translations that alert recipients could spot easily.
South Korea has one of the world's most connected populations, with near-universal smartphone adoption and widespread use of domestic messaging platforms. That digital density gives attackers more entry points but also generates more forensic evidence. Investigators are examining server logs, email headers, and authentication records to trace the intrusion path.
The country's Personal Information Protection Act imposes strict penalties for data leaks, including fines of up to 3% of annual revenue for negligent security. Whether religious organizations face the same enforcement pressure as corporations remains an open legal question. South Korean regulators have not yet commented publicly on the case.
AI-assisted cyberattacks have risen sharply across Asia over the past two years. Security researchers have documented campaigns in which large language models generate convincing spear-phishing messages, automate code exploitation, and adapt in real time to a target's responses. The technology lowers the skill barrier for attackers and increases the volume of attempts.
For churches, the reputational damage may prove as costly as the regulatory fallout. Congregants trust pastors with deeply personal information, and any sign that data was mishandled can erode that trust for years. The two churches have begun notifying potentially affected members and have set up hotlines to answer questions.
Cybersecurity analysts note that religious institutions across the United States and Europe have faced similar threats, though few have confirmed AI involvement. The South Korean case could become a reference point for how faith organizations worldwide assess their exposure to AI-driven attacks.
The investigation continues, and officials have not ruled out the possibility that the attackers are based outside South Korea. The cybersecurity firm said it is sharing technical indicators with law enforcement but declined to provide further details. Church leaders have asked congregants to monitor their accounts for unusual activity and to report suspicious messages.