Vatican's Official Prayer App Leaks 700K+ Global Users' PII

Summary

The Vatican's official prayer app has experienced a data leak, exposing the Personally Identifiable Information (PII) of over 700,000 users worldwide. The compromised data includes names, email addresses, location, and site status, accessible through an unprotected API endpoint.

IFF Assessment

FOE

This incident represents a significant data exposure, directly impacting user privacy and potentially enabling further malicious activities against affected individuals.

Defender Context

This incident highlights the critical need for robust API security and thorough data handling practices, even for non-profit or religious organizations. Defenders should be aware of the potential for PII exposure through misconfigured APIs and ensure regular security audits of all exposed endpoints.

Read Full Story →