AI-Driven Cyberattack Exposes Data of Hundreds of Thousands at South Korean Churches

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Attackers used AI tools in a cyberattack on two major South Korean churches, Yoido Full Gospel Church and Sarang Church, leading to the potential leak of personal data of up to 850,000 members. Evidence of AI-generated attack reports and automated methods was found. Authorities and churches are investigating and responding.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions the use of AI tools by attackers in conducting the cyberattack, which led to the leakage of sensitive personal data of a large number of individuals. This constitutes a violation of fundamental rights related to privacy and data protection. The AI system's involvement is direct in the use of AI-enabled methods to carry out the attack, causing realized harm. Hence, this qualifies as an AI Incident under the framework, as the AI system's use directly led to a breach of rights and harm to individuals.[AI generated]
AI principles
Privacy & data governanceRespect of human rights

Industries
Digital security

Affected stakeholders
General publicBusiness

Harm types
Human or fundamental rightsReputational

AI system task:
Content generation


Articles about this incident or hazard