BenchmarksNewsPC Components

Vatican app leaks user data for six months exposing 700k users

Featured image Vatican app leaks user data for six months exposing 700k users

The digital world is often filled with stories of massive corporate data breaches, but sometimes the most vulnerable targets are found in the quiet corners of everyday applications. In a startling revelation that exposed profound security flaws within a major religious application, researchers discovered that the widely used “Click To Pray” app possessed zero security, leaving a substantial number of users’ private information dangerously exposed.

The discovery, made in early 2026, demonstrated an alarming vulnerability: the app’s Application Programming Interface (API) endpoint allowed anyone to access sensitive user data simply by inputting user IDs. This meant that personal details, including first names, last names, email addresses, and birthdates, were accessible through this easily exploitable pathway.

While seemingly a prayer application might not be on the radar of major cyber threats, the sheer volume of exposed data presents a significant risk. Security experts noted that obtaining just names and email addresses is often enough for malicious actors to initiate sophisticated phishing campaigns. Given that many users of such applications are older demographics who may be less familiar with advanced security protocols, this leak created an open invitation for scammers looking to harvest personal details.

The system’s flaws were even more egregious. The method used to generate user IDs was sequential, and critically, the validation hashes—the keys used to verify account signups—were stored in cleartext. This meant that an attacker with API access could not only extract information but also easily verify any account, effectively bypassing security checks.

The potential impact of this exposure is substantial. As of July 2026, the database contained nearly 720,000 accounts. Even if a small percentage of these users fell victim to phishing scams, the scale of the breach translates into thousands of individuals potentially exposed to financial fraud and identity theft.

When security researchers brought these critical vulnerabilities to the attention of relevant parties, they faced silence. Despite emailing nine individuals with details of the flaws, the researchers received no response or notice of corrective action for six months. This lack of engagement amplified the sense that the system’s security was overlooked.

It wasn’t until external scrutiny forced a response that the app developers addressed the serious lapses in security. The news story published by a security journalist brought the vulnerability into the public light, prompting immediate fixes to protect user data and ensure that future security protocols are robust and transparent.