Vatican's Click to Pray App Vulnerability Exposes 700,000 Users to Data Theft
> cd .. / HUB_EDITORIALE
News

Vatican's Click to Pray App Vulnerability Exposes 700,000 Users to Data Theft

[2026-07-26] Author: Meteora Web Redazione
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

A critical security flaw in the Vatican's official prayer app, Click to Pray, has exposed the personal data of approximately 720,000 users worldwide for over six months. Security researcher BobDaHacker discovered the vulnerability in January 2026, but developers only fixed it after Dark Reading published an investigative story in July. In the interim, names, email addresses, and birthdates were freely accessible through the app's API.

Zero authentication and unprotected API allowed data access

BobDaHacker found that the app's API required no authentication: anyone could retrieve personal information by simply entering sequential user IDs. The lack of rate limiting enabled bulk downloading of the entire user database with automated GET requests. Additionally, the validation_hash used for account verification was stored in plaintext, allowing unauthorized account activation. Emails to nine contacts went unanswered for half a year, a fact confirmed by security journalist Nate Nelson of Dark Reading.

Sponsored Protocol

Elderly users especially vulnerable to targeted phishing

Most Click to Pray users are elderly individuals with limited technical expertise. Cybercriminals could have used the harvested names and emails to craft personalized phishing messages with a high success rate. Even if just one percent of the 720,000 users fallen for a scam, over 7,000 people could have lost money. While no financial data was exposed, the breach poses a serious digital safety risk for the faithful. For more on cybersecurity threats to small businesses, read about OpenAI develops an autonomous hacker — what it means for European SMEs.

Six months of silence and a fix only after media coverage

Despite BobDaHacker's reports to nine email addresses, no response or patch arrived. Only when Dark Reading published the story in late July did the developers finally address the flaw. The researcher received no official acknowledgment. This incident highlights how even trustworthy organizations like the Holy See can overlook basic security. Phishing remains a pervasive threat; Wikipedia provides an overview of how these scams operate.

Sponsored Protocol

As cybersecurity becomes ever more critical — seen in projects like Massachusetts' V2G pilot using EV batteries to stabilize the grid, covered in this article — incidents like this remind us that no organization is immune to fundamental data protection errors.

Source: https://www.tomshardware.com/tech-industry/cyber-security/security-flaw-in-vaticans-click-to-pray-app-leaves-over-700-000-global-users-exposed-app-has-been-leaking-user-data-for-over-six-months-and-still-does

> share
Meteora Web Redazione

> AUTHOR_EXTRACTED

Meteora Web Redazione

La redazione di Meteora Web Agency: ingegneri informatici e professionisti del digitale che pubblicano ogni giorno news e approfondimenti su tecnologia, software, marketing e innovazione.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()