Pope’s Worldwide Prayer Network: Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does

Pope’s Worldwide Prayer Network: Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does

Vatican-Linked Prayer App Exposed 720,000 Users’ Data Due to Zero Security

In January 2026, security researcher BobDaHacker uncovered critical vulnerabilities in Click To Pray, the official prayer app of the Pope’s Worldwide Prayer Network, exposing sensitive user data. The app’s API lacked basic security measures, allowing unrestricted access to personal information including names, email addresses, and birthdates simply by inputting sequential user IDs.

With no rate limiting on the API, attackers could automate data harvesting, retrieving details from all 720,000 accounts as of July 2026. The app’s validation_hash was also stored in plaintext, enabling account verification via email a feature that could be exploited for phishing. Given the app’s user base, which likely includes older, less tech-savvy individuals, the exposed data presented a prime target for cybercriminals.

Despite multiple attempts to alert the app’s developers, BobDaHacker received no response for six months. Only after the issue was publicized by Dark Reading in late 2026 were the vulnerabilities patched though the researcher received no acknowledgment. The incident highlights the risks of overlooked security in even niche applications, with potential consequences for thousands of users.

Source: https://www.tomshardware.com/tech-industry/cyber-security/security-flaw-in-vaticans-click-to-pray-app-leaves-over-700-000-global-users-exposed-app-has-been-leaking-user-data-for-over-six-months-and-still-does

MEJ : Mouvement Eucharistique des Jeunes cybersecurity rating report: https://www.rankiteo.com/company/mej

"id": "MEJ1785018222",
"linkid": "mej",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '720,000',
                        'industry': 'Non-Profit/Religious',
                        'name': 'Pope’s Worldwide Prayer Network',
                        'type': 'Religious Organization'}],
 'attack_vector': 'API Misconfiguration',
 'data_breach': {'data_encryption': 'No (validation_hash stored in plaintext)',
                 'data_exfiltration': 'Possible via automated harvesting',
                 'number_of_records_exposed': '720,000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information)',
                 'type_of_data_compromised': ['Names',
                                              'Email addresses',
                                              'Birthdates']},
 'date_detected': '2026-01',
 'date_publicly_disclosed': '2026-10',
 'date_resolved': '2026-10',
 'description': 'Security researcher BobDaHacker uncovered critical '
                'vulnerabilities in *Click To Pray*, the official prayer app '
                'of the Pope’s Worldwide Prayer Network, exposing sensitive '
                'user data. The app’s API lacked basic security measures, '
                'allowing unrestricted access to personal information '
                'including names, email addresses, and birthdates simply by '
                'inputting sequential user IDs. The vulnerabilities included '
                'no rate limiting and plaintext storage of a validation_hash, '
                'enabling automated data harvesting and potential phishing '
                'attacks.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to the '
                                       'Pope’s Worldwide Prayer Network',
            'data_compromised': '720,000 user records',
            'identity_theft_risk': 'High (names, email addresses, birthdates '
                                   'exposed)',
            'systems_affected': 'Click To Pray app API'},
 'investigation_status': 'Resolved',
 'lessons_learned': 'The incident highlights the risks of overlooked security '
                    'in niche applications, especially those targeting '
                    'vulnerable populations like older, less tech-savvy users. '
                    'Basic security measures (e.g., rate limiting, encryption) '
                    'are critical even for non-commercial apps.',
 'post_incident_analysis': {'corrective_actions': ['Patching vulnerabilities',
                                                   'Improving API security',
                                                   'Potential establishment of '
                                                   'a vulnerability disclosure '
                                                   'program'],
                            'root_causes': ['Lack of API security controls',
                                            'No encryption of sensitive data',
                                            'No vulnerability disclosure '
                                            'process']},
 'recommendations': ['Implement rate limiting on APIs to prevent automated '
                     'data harvesting',
                     'Encrypt sensitive data (e.g., validation_hash) to '
                     'prevent plaintext exposure',
                     'Establish a clear vulnerability disclosure process to '
                     'respond to security researchers promptly',
                     'Conduct regular security audits for all applications, '
                     'regardless of their perceived risk level'],
 'references': [{'date_accessed': '2026-10', 'source': 'Dark Reading'}],
 'response': {'communication_strategy': 'No initial response to researcher; '
                                        'public disclosure via Dark Reading',
              'containment_measures': 'Vulnerabilities patched after public '
                                      'disclosure',
              'remediation_measures': 'API security improvements (rate '
                                      'limiting, encryption of sensitive '
                                      'data)'},
 'title': 'Vatican-Linked Prayer App Exposed 720,000 Users’ Data Due to Zero '
          'Security',
 'type': 'Data Breach',
 'vulnerability_exploited': ['Lack of rate limiting',
                             'Plaintext storage of validation_hash']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.