Wire flash
TechVatican's Click to Pray App Exposed 720,000 Users' Data via Unauthenticated API
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
A security researcher known as BobDaHacker discovered that the Vatican-linked 'Click to Pray' app, part of the Pope's Worldwide Prayer Network, had zero authentication on its API, allowing anyone to access user data including names, email addresses, and birthdates by simply entering sequential user IDs. The app had no rate limiting, enabling bulk data extraction. The researcher notified nine individuals at the app's development team in January 2026 but received no response for six months. After contacting journalist Nate Nelson of Dark Reading, who published a story, the security flaws were finally fixed. The app had nearly 720,000 accounts as of July 2026, with many users likely older and less tech-savvy, making them prime targets for phishing scams. The researcher was never acknowledged by the app's makers.
Source report
A security researcher has discovered that Click To Pray, the official prayer app of the Pope’s Worldwide Prayer Network, had no meaningful security protections in place, leaving user data exposed.
Discovery and Lack of Response
According to a researcher using the alias BobDaHacker, the vulnerability was identified in January 2026. The app's API endpoint allowed anyone to access user data simply by entering user IDs. The researcher emailed nine individuals associated with the app about the issue but received no response. After six months with no action taken, the vulnerabilities remained unaddressed.
Exposed Data
The information accessible from the app's database included:
- First and last names
- Email addresses
- Birthdates
While this may seem limited, the combination of names and email addresses is sufficient for malicious actors to launch targeted phishing campaigns. BobDaHacker noted that the app's user base likely includes many older, less tech-savvy individuals, making it an attractive target for scammers.
Additional Security Weaknesses
The researcher also highlighted several other flaws:
- Sequential user IDs – New accounts were assigned IDs in sequence, making it easy to enumerate users.
- No rate limiting – The API did not restrict the number of requests, allowing automated data harvesting with a single GET request per user.
- Plaintext validation hash – The
validation_hashused to verify account signups was stored in clear text, enabling anyone with API access to validate accounts. - Email security issues – Even legitimate emails from the app appeared suspicious, resembling phishing messages.
Scale of the Risk
As of July 2026, the app had approximately 720,000 accounts. While this is small compared to major data breaches, the researcher warned that even a 1% response rate from harvested email addresses could result in over 7,000 individuals potentially losing money to scammers.
Resolution
After six months of silence, BobDaHacker contacted Nate Nelson, a security journalist at Dark Reading, who published a story on the issue. Only after the news broke were the security lapses fixed. The researcher noted that they never received acknowledgment from the app's developers.
"Hopefully, no other hackers were aware of the weaknesses of the Click To Pray app."
Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, and reviews in your feeds.
Source
Latest from Tom's HardwareWestern
Part of this Story
Vatican's Click to Pray App Exposed 720,000 Users' Data for Over Six Months