● Data Breaches

Vatican Prayer Application Exposes Personal Data of Over 700,000 Users

July 24, 2026 · snewle
Vatican Prayer Application Exposes Personal Data of Over 700,000 Users

The Vatican’s official prayer application has exposed the personal information of more than 700,000 users worldwide through a security flaw. The Vatican prayer app leak occurred due to an unsecured API endpoint that allowed anyone with a web browser to access sensitive user data without authentication.

The exposed information includes users’ full names, email addresses, geographic location data, and site status information. This vulnerability represents a significant privacy breach for individuals who downloaded the application to support their spiritual practices through the Vatican’s official platform.

How Was the Data Exposed?

The security weakness stemmed from a porous API endpoint that failed to implement proper access controls. The vulnerable endpoint made it trivially easy for anyone to extract user information simply by accessing it through a standard web browser, requiring no specialized hacking tools or technical expertise. This type of misconfiguration represents a fundamental security oversight in the application’s design and deployment.

What Information Was at Risk?

The compromised data included several categories of personally identifiable information. User names were fully exposed, along with their email addresses, which could potentially be used for phishing attacks or spam campaigns. Location data revealed where users were accessing the prayer application from around the world. Additionally, the site status information for each user was accessible, though the specific nature of this status field was not detailed in the disclosure.

Understanding the Impact

With over 700,000 users affected, this breach touches individuals across the globe who trusted the Vatican’s official application with their personal information. The exposure of email addresses combined with names and location data creates multiple vectors for potential abuse, including targeted phishing campaigns, identity theft attempts, and unwanted contact. Users of faith-based applications often have heightened expectations of privacy and security, making this vulnerability particularly concerning for the affected community.

The ease with which this data could be accessed—requiring only browser access rather than sophisticated attack methods—suggests the vulnerability may have existed for an extended period and could have been discovered by malicious actors before being reported.

Source: Dark Reading