< Back to all clusters
[TECHNOLOGY] · Vatican City · 5 sources

Vatican prayer app ‘Click to Pray’ leaks data of over 700,000 users

The Vatican’s official prayer app, Click to Pray, exposed personal information of more than 700,000 registered users for several months. A security researcher using the handle “BobDaHacker” identified an insecure direct object reference (IDOR) flaw in January 2026 that let anyone query the app’s API with a sequential numeric user ID and retrieve names, email addresses, birth dates, country of origin and account status without authentication. The vulnerability also revealed a verification code for new accounts, bypassing email confirmation.

The app, launched in 2019 by Pope Francis and offered in seven languages on iOS, Android and the web, had 719,517 accounts at the time of the breach. Despite repeated warnings, the operators did not respond, and the flaw remained live until it was finally patched months later. Researchers warned that the exposed data could be used for targeted phishing attacks impersonating the Vatican. The incident highlights common web‑application security gaps and the need for prompt vulnerability remediation.