INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Religious Institutions Confirm Cyber Attack Exposes Large-Scale Personal Information
| 2026-10-06 21:43 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A stolen MinIO account from a US-based religious platform was reused for domestic attacks in South Korea on October 6, 2026. The attacker secured the 'sysadmin' privileges of an MSSQL database and accessed internal systems, including ERP servers, groupware, NAS file servers, and internal messenger conversation records. Approximately three hundred thirty thousand cases of donor information, nine hundred sixty thousand resident registration numbers, sixty-eight thousand eight hundred electronic documents, fourteen thousand seven hundred six internal messenger conversation records, and forty-seven point three gigabytes of data were leaked externally. The attackers used webshells and vulnerabilities in authentication and authorization to gain access, then expanded their infiltration range by moving within the institution after initial access, resulting in an incremental expansion of the attack range.
Technical Mitigations AI-generated
• Patch the MSSQL database to secure 'sysadmin' privileges and prevent webshell-based ERP infiltration.
• Regularly monitor for Insecure Direct Object Reference (IDOR) vulnerabilities in authentication and authorization systems, as well as groupware servers.
• Implement data encryption on internal NAS and file servers to protect sensitive information from unauthorized access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
2026/10/06
Attackers reused a stolen MinIO account from a US-based religious platform to access and leak large-scale personal information of members at two domestic Korean religious institutions.
Click on any entity below to view its context and source!
organisation
ERP
ERP and groupware used to leak large-scale personal information..
organisation
Oasis Security
Cyber threat intelligence company Oasis Security has analyzed the tools, logs, and stolen data from the attacker's overseas server, and reconstructed the infiltration path and scope of damage for two large Korean religious institutions.
organisation
Webshell
Webshell-based ERP infiltration...
organisation
Orasis Security
Orasis Security has confirmed that the data stolen by overseas attackers from the religious institution includes a large amount of internal data.
organisation
NAS
The attackers did not stop at accessing the database and expanded their access range to include internal NAS and file servers.
organisation
SMB
They secured account information stored in internal settings files and accessed the NAS's SMB shared area, collecting data from the database and file servers and temporarily storing it in the internal system before transmitting it to the external MinIO infrastructure.
organisation
SIMS
The attack scope did not limit to the groupware and SIMS systems.
organisation
SSO
Attackers used the SSO feature of the groupware to access the SAP portal without additional login, and during this process, they obtained the information of employees and employee photos.
organisation
SAP
Attackers used the SSO feature of the groupware to access the SAP portal without additional login, and during this process, they obtained the information of employees and employee photos.
victims
286 employee information
Oasis Security confirmed that they found approximately eighty thousand nine thousand information of members and 286 employee information from the attacker's server, and through this, they confirmed that related information was leaked to the external attack infrastructure.
Tactical Metrics
Metrics
victims
286
Employee Information
Click for context!
Oasis Security confirmed that they found approximately eighty thousand nine thousand information of members and 286 employee information from the attacker's server, and through this, they confirmed that related information was leaked to the external attack infrastructure.
Intelligence Sources
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T10:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
9x
organisation
Identified Entity
ERP
entity
2x
target region
Target Country
United States
country
Contextual Telemetry
Context Block
2 METRICS
general metric
Locations
2
locations
victims
Employee Information
286
employee information
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.