< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 7 sources · 3 days · First seen · Last updated

Categories: TECHNOLOGY

Vatican prayer app data breach

Entities: Vatican City · Click to Pray · BobDaHacker · Pope’s Worldwide Prayer Network · Pope Francis

Overview

In early January 2026 a security researcher (BobDaHacker) identified an insecure direct object reference (IDOR) flaw in the Vatican’s official “Click to Pray” application. The vulnerability let anyone query the app’s API with sequential numeric user IDs and retrieve full personal records—including names, emails, birth dates, country of origin and account status—for the roughly 719,000 registered users.

The researcher reported the flaw to the Vatican, but the organization did not respond. The flaw remained live for several months, exposing user data that could be leveraged for targeted phishing attacks impersonating the Vatican. A second issue was later uncovered: the registration endpoint returned the email‑verification hash, allowing account creation without access to the user’s inbox, while confirmation emails failed basic SPF/DKIM/DMARC checks.

The vulnerabilities became public in late July 2026 after a journalist inquiry, prompting the Vatican to finally patch the IDOR flaw and address the registration weakness. The incident highlighted lingering security gaps in the app, which had been launched in 2019 and offered in seven languages across iOS, Android and the web.

Timeline

  1. about 5 hours ago

    [TECHNOLOGY] 2 sources
    Vatican Prayer App Exposes 719,000 Users' Personal Data

    A critical IDOR bug in the Vatican's Click to Pray app leaked personal data of about 719,000 users and allowed account creation without email verification.

  2. 2 days ago

    [TECHNOLOGY] 5 sources
    Vatican prayer app ‘Click to Pray’ leaks data of over 700,000 users

    A security flaw in the Vatican’s Click to Pray app let anyone retrieve personal data of over 700,000 users for months until it was finally patched, raising phishing concerns.

Sources

all-about-security.de · blogspan.net · ibtimes.com.au · it-daily.net · pcgameshardware.de · psnews.ro · theregister.co.uk