“Even God Won’t Help”: Pope Leo’s Prayer App Suffers Devastating Data Breach – Wide Open Country

Do you use a prayer app? What about Pope Leo’s? Well, if you have, you should be worried about a pretty devastating data breach.
Do you use a prayer app? As technology becomes more and more of a part of our daily lives, it’s something that’s only going to surge in popularity.

And it’s catching on in many denominations. Even the Catholic Church wanted to get ahead of the curve, so they made their own Pope-approved app.

In case you’re unaware, Click to Pray is the official app of the Pope’s Worldwide Prayer Network, which is, as the name suggests, chaired by the Pope. It displays Leo’s daily intentions to many hundreds of thousands.

But there’s been a bit of a problem with it in recent days. As reported by Dexerto, Pope Leo’s prayer app has exposed the personal details of over 700,000 devotees.

And the worst part? It all stemmed from a vulnerability that was left for months. A cybersecurity researcher named BobDaHacker found that there was a lapse of security in the app.

It took six months for the security hole to be patched. And yet, no one from the network spoke up about it.
Well, it’s pretty techy—but let’s break it down. The problem was called an “IDOR”, which stands for an “In-Direct Object Reference”. You know how, when you log in to an account on certain websites, there might be a ticket number or an account number?

Well, as per OWASP, an IDOR vulnerability is where an attacker essentially changes that number. And, in the case of the Pope’s prayer app, there weren’t any checks in place to make sure that person had the credentials.

Think of it like a lock on a door. You know your key fits, right? Well, if someone can guess the shape of your key at random and make it fit into the door, you’re toast. And if there are no security guards (i.e., permission checks from the website), you’ve just been burgled (had your data stolen).

So you’re left with a glaring vulnerability that can leave your personal details stolen. We’re not sure how much data, if any, was stolen, unfortunately.

When these attacks happen because of a security hole, they’re very quiet. People don’t find out until months later… if at all. We hope that no data was taken from Pope Leo’s prayer app.

source
This is a newsfeed from leading technology publications. No additional editorial review has been performed before posting.

Continue Your AI Leadership Journey

Turn insight into action with CDO TIMES.

CDO TIMES helps executives move from AI awareness to AI execution through practical frameworks, tools, executive research, and advisory support.

Explore the Frameworks

Continue with Enterprise AI 2030, HI + AI = ECI, AI Governance, and executive playbooks.

Explore Enterprise AI 2030 →

Use the Free Tools

Assess readiness, estimate AI ROI, model AI costs, and prioritize AI initiatives.

Open Executive Tools →

Read the Book

Explore the HI + AI = ECI leadership model in The AI-Ready Leader.

Order The AI-Ready Leader →

Go deeper with CDO TIMES Pro.

Unlock premium research, executive playbooks, templates, advanced tools, and member-only briefings.

Join CDO TIMES Pro

Need executive help?

Explore advisory, workshops, fractional CIO/CDO/CISO/CAIO support, and AI operating model design.

Explore Advisory →

Attend executive events

Join leadership forums, executive dinners, webinars, and strategic AI briefings.

View Events →

Build AI capability

Use CDO TIMES Academy for executive learning, AI leadership development, and implementation training.

Explore Academy →

Leave a Reply