Vatican's Click to Pray App Exposed 720,000 Users' Data for Over Six Months
A security researcher known as BobDaHacker discovered that the Vatican-linked 'Click to Pray' app, part of the Pope's Worldwide Prayer Network, had zero authentication on its API, allowing anyone to access user data including names, email addresses, and birthdates by simply entering sequential user IDs. The app had no rate limiting, enabling bulk data extraction. The researcher notified nine individuals at the app's development team in January 2026 but received no response for six months. After contacting journalist Nate Nelson of Dark Reading, who published a story, the security flaws were finally fixed. The app had nearly 720,000 accounts as of July 2026, with many users likely older and less tech-savvy, making them prime targets for phishing scams. The researcher was never acknowledged by the app's makers.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection