Security firm Oasis Security found data from two of Seoul’s largest megachurches, Yoido Full Gospel Church and Sarang Church, on an overseas attacker-controlled server, alongside attack logs referencing AI “sub-agents” and automated-looking reports. Attackers reportedly used a webshell to gain administrator access to Yoido’s enterprise resource planning database, exposing a log of changes affecting roughly 850,000 members’ records, while Sarang Church reported a smaller breach of about 89,000 member records and 286 employee records via stolen credentials. South Korea’s president said AI was believed to have been used in the attacks, and both churches have reported the incidents to authorities and begun remediation.