Wire flash
TechVatican's Click to Pray app exposed 720,000 users' data for over six months due to unauthenticated API
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
A security researcher, BobDaHacker, discovered that the Vatican-linked 'Click to Pray' app had zero authentication on its API, allowing anyone to access user data including names, email addresses, and birthdates by simply entering sequential user IDs. The app, part of the Pope's Worldwide Prayer Network, had nearly 720,000 accounts as of July 2026. The researcher notified nine individuals in January 2026 but received no response for six months. The vulnerability was only fixed after security journalist Nate Nelson of Dark Reading published a story about it. The lack of rate limiting made bulk data extraction trivial, and the validation_hash was stored in plaintext. The researcher expressed concern that older, less tech-savvy users were particularly vulnerable to phishing attacks. No acknowledgment was given to the researcher by the app's developers.
Source report
A security researcher has discovered that Click To Pray, the official prayer app of the Pope’s Worldwide Prayer Network, had no meaningful security protections, leaving user data exposed to anyone who knew where to look.
Discovery and Lack of Response
According to the researcher, who goes by the handle BobDaHacker, the vulnerability was identified in January 2026. The app’s API endpoint allowed anyone to access user data simply by entering user IDs. No authentication or rate limiting was in place.
BobDaHacker reported the issue to nine individuals associated with the app but received no response and observed no changes for six months.
Exposed Data
The information accessible from the app’s database included:
- First and last names
- Email addresses
- Birthdates
While this may seem limited, security experts note that names and email addresses are sufficient for bad actors to launch targeted phishing campaigns. BobDaHacker also highlighted that many of the app’s users are likely older and less tech-savvy, making them particularly vulnerable to scams.
Additional Security Issues
The researcher also found that:
- User IDs were assigned sequentially, making it easy to scrape the entire user database automatically.
- The API had no rate limiting, allowing an attacker to capture all user data with a single GET request per user.
- The validation_hash, used to verify account signups, was stored in plaintext, enabling anyone with API access to verify accounts simply by opening an inbox.
- The app’s emails themselves had security issues, making even legitimate messages appear as phishing attempts.
Scale of the Risk
As of July 2026, the app had approximately 720,000 accounts. While this is small compared to major data breaches, the potential impact is significant. If just 1% of users responded to a scammer who harvested their email addresses from the app, that would represent more than 7,000 individuals who could lose money as a result of the leak.
Resolution
After six months of silence, BobDaHacker contacted Nate Nelson, a security journalist at Dark Reading, who published a story on the issue. Only after the news went live were the security lapses fixed. The researcher noted that they were never acknowledged by the app’s developers.
It remains unclear whether any other hackers had discovered the vulnerabilities before they were patched.
Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, and reviews in your feeds.
Source
Latest from Tom's HardwareWestern
Part of this Story
Vatican's Click to Pray App Exposed 720,000 Users' Data for Over Six Months