← Back to Feed
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
July 24, 2026 · Dark Reading · Severity: MEDIUM
A Vatican prayer application exposed the personal data of over 700,000 users through a poorly secured API that leaked names, email addresses, country of origin, and application status information globally. The porous API did not require proper authentication or authorization checks, allowing anyone who discovered the endpoint to access the complete user database. The breach underscores how faith-based and nonprofit applications handling sensitive user data often lack the security scrutiny applied to commercial platforms, and how simple API misconfigurations can expose vast amounts of personal information with global reach.
Key Takeaways
- A Vatican prayer app API leaked personal data of over 700,000 users including names, emails, and country information.
- The API lacked proper authentication and authorization controls, allowing unrestricted access to the entire user database.
- Faith-based and nonprofit applications often receive less security scrutiny than commercial platforms despite handling sensitive data.