← Back to Feed
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
July 24, 2026 · Dark Reading · Severity: MEDIUM
A Vatican prayer application exposed the personal data of over 700,000 users through a poorly secured API that leaked names, email addresses, country of origin, and application status information globally. The porous API did not require proper authentication or authorization checks, allowing anyone who discovered the endpoint to access the complete user database. The breach underscores how faith-based and nonprofit applications handling sensitive user data often lack the security scrutiny applied to commercial platforms, and how simple API misconfigurations can expose vast amounts of personal information with global reach.
Key Takeaways
- A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned.