Loading prices…
STKR NewsSTKR News0 of 3 free this month
AI

Hackers Used AI Agents to Raid a Megachurch's Database, Exposing 850,000 Members

A breach at a massive South Korean church exposes how AI agents are turning traditional database exploits into automated, high-speed heists that small dev teams aren't ready for.

Originally on Decrypt →
AB

Adrian Boysel

Contributor

Oct 7, 2026

4 min read

Photo illustration / STKR News

We have entered the era of the automated heist. For years, security experts warned that AI would eventually be used to scale cyberattacks. That future just arrived in Seoul, and it provides a sobering case study for anyone building in the crypto or data sectors.

Yoido Full Gospel Church, one of the largest congregations on the planet, recently confirmed a massive data breach affecting roughly 850,000 members. On the surface, it looks like a standard database raid: names, phone numbers, and addresses leaked. But the underlying mechanics, as reported by security researchers, reveal a shift in the threat landscape. This wasn't a lone hacker poking at a firewall for weeks; it was an operation assisted by AI agents.

The Shift from Script Kiddies to AI Agents

In the old days, a hacker had to manually probe for vulnerabilities, test different SQL injection strings, and wait for responses. Even with automation tools, there was a level of human oversight required to pivot when a defense was triggered. AI agents change the math. They don't get tired, they learn from the response of the server in real-time, and they can execute multi-stage attacks at a speed no human operator could match.

For the builders reading this, the takeaway isn't that AI is 'evil.' It is that the barrier to entry for sophisticated, high-volume attacks has just hit zero. If an AI can be prompted to find a loophole in a church database, it can certainly be prompted to find a flaw in your smart contract or your user authentication flow.

Why Databases Are Still the Weakest Link

It is ironic that in a world obsessed with decentralization and high-level encryption, we are still losing the battle at the database level. The Yoido breach exposed the basic PII (Personally Identifiable Information) of nearly a million people. In the crypto world, we often talk about 'on-chain' security, but we forget that most Web3 applications still rely on centralized 'off-chain' databases for user profiles, email lists, and frontend metadata.

When an AI agent targets these legacy structures, it doesn't need to crack a private key. It just needs to find one unpatched plugin or one poorly configured API endpoint. Once the agent gets a foothold, it can scrape the entire directory before a human admin even gets the first alert on their dashboard.

The Reality for Builders and Founders

If you are building a product today, you have to assume that your attack surface is being scanned by bots that are smarter than the ones we dealt with two years ago. We are moving away from 'static' threats toward 'generative' threats. This means your security posture can't be a checklist you finish once a quarter. It has to be as dynamic as the agents trying to break in.

What this means for your tech stack:

  • Obsessive Rate Limiting: AI agents thrive on high-frequency requests. If your API doesn't have aggressive, intelligent rate limiting, you are essentially leaving the door open for an automated moving van.
  • Zero Trust Architecture: Stop assuming that once someone is 'inside' the network, they are safe. Every internal request should be validated as if it came from the public internet.
  • AI vs AI: You cannot defend against machine-speed attacks with human-speed monitoring. You need to be employing AI-driven security tools that can recognize and kill anomalous patterns in milliseconds.

The Human Cost of Automated Failure

We often talk about data breaches in terms of numbers. '850,000 records' sounds like a statistic. But for a founder, that number represents 850,000 instances of broken trust. In the case of a church, this data could be used for targeted phishing, social engineering, or even physical harassment. In the context of a crypto project, this is the data that leads to SIM swaps and drained wallets.

The attackers aren't just looking for credit card numbers anymore. They are looking for the social graph. By using AI to map out the relationships within a database, they can craft incredibly convincing deepfake or phishing campaigns. The church breach is just the top of the funnel for a much larger series of scams.

A Skeptical Look at the Future

I am generally skeptical of the 'AI will destroy everything' narrative, but I am equally skeptical of founders who think their current security setup is 'good enough.' The Yoido incident proves that even non-tech organizations are now targets for high-tech automated warfare. If a church in Seoul is being hit by AI agents, your DeFi protocol or AI startup is already on a list somewhere.

We are entering a period where the 'defensive' side of the ball is lagging behind the 'offensive' side. It’s cheaper to buy an API key for a Large Language Model and tell it to find bugs than it is to hire a full-time security team to prevent them. That imbalance is going to lead to a very messy 24 months for the industry.

Building for Resilience

The solution isn't to stop building or to go back to paper records. The solution is to change how we think about data. If you don't need to store it, don't. If you do need to store it, encrypt it at the field level. And most importantly, build with the assumption that your database will be probed by an intelligence that doesn't sleep.

The Yoido breach is a warning shot. It’s not just a story about a church; it’s a story about the new baseline for cybercrime. The agents are here, they are efficient, and they are looking for the path of least resistance. Make sure your project isn't it.


Read the original at Decrypt →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses