Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 7 sources · 3 days · First seen · Last updated
Categories: TECHNOLOGY
Vatican prayer app data breach
Entities: Vatican City · Click to Pray · BobDaHacker · Pope’s Worldwide Prayer Network · Pope Francis
Overview
In early January 2026 a security researcher (BobDaHacker) identified an insecure direct object reference (IDOR) flaw in the Vatican’s official “Click to Pray” application. The vulnerability let anyone query the app’s API with sequential numeric user IDs and retrieve full personal records—including names, emails, birth dates, country of origin and account status—for the roughly 719,000 registered users.
The researcher reported the flaw to the Vatican, but the organization did not respond. The flaw remained live for several months, exposing user data that could be leveraged for targeted phishing attacks impersonating the Vatican. A second issue was later uncovered: the registration endpoint returned the email‑verification hash, allowing account creation without access to the user’s inbox, while confirmation emails failed basic SPF/DKIM/DMARC checks.
The vulnerabilities became public in late July 2026 after a journalist inquiry, prompting the Vatican to finally patch the IDOR flaw and address the registration weakness. The incident highlighted lingering security gaps in the app, which had been launched in 2019 and offered in seven languages across iOS, Android and the web.
Timeline
-
about 5 hours ago
[TECHNOLOGY] 2 sourcesVatican Prayer App Exposes 719,000 Users' Personal DataA critical IDOR bug in the Vatican's Click to Pray app leaked personal data of about 719,000 users and allowed account creation without email verification.
-
2 days ago
[TECHNOLOGY] 5 sourcesVatican prayer app ‘Click to Pray’ leaks data of over 700,000 usersA security flaw in the Vatican’s Click to Pray app let anyone retrieve personal data of over 700,000 users for months until it was finally patched, raising phishing concerns.
Sources
all-about-security.de · blogspan.net · ibtimes.com.au · it-daily.net · pcgameshardware.de · psnews.ro · theregister.co.uk