A critical security flaw in the Vatican's official prayer app, Click to Pray, has exposed the personal data of approximately 720,000 users worldwide for over six months. Security researcher BobDaHacker discovered the vulnerability in January 2026, but developers only fixed it after Dark Reading published an investigative story in July. In the interim, names, email addresses, and birthdates were freely accessible through the app's API.
Zero authentication and unprotected API allowed data access
BobDaHacker found that the app's API required no authentication: anyone could retrieve personal information by simply entering sequential user IDs. The lack of rate limiting enabled bulk downloading of the entire user database with automated GET requests. Additionally, the validation_hash used for account verification was stored in plaintext, allowing unauthorized account activation. Emails to nine contacts went unanswered for half a year, a fact confirmed by security journalist Nate Nelson of Dark Reading.
Sponsored Protocol
Elderly users especially vulnerable to targeted phishing
Most Click to Pray users are elderly individuals with limited technical expertise. Cybercriminals could have used the harvested names and emails to craft personalized phishing messages with a high success rate. Even if just one percent of the 720,000 users fallen for a scam, over 7,000 people could have lost money. While no financial data was exposed, the breach poses a serious digital safety risk for the faithful. For more on cybersecurity threats to small businesses, read about OpenAI develops an autonomous hacker — what it means for European SMEs.
Six months of silence and a fix only after media coverage
Despite BobDaHacker's reports to nine email addresses, no response or patch arrived. Only when Dark Reading published the story in late July did the developers finally address the flaw. The researcher received no official acknowledgment. This incident highlights how even trustworthy organizations like the Holy See can overlook basic security. Phishing remains a pervasive threat; Wikipedia provides an overview of how these scams operate.
Sponsored Protocol
As cybersecurity becomes ever more critical — seen in projects like Massachusetts' V2G pilot using EV batteries to stabilize the grid, covered in this article — incidents like this remind us that no organization is immune to fundamental data protection errors.