Wire flash
TechVatican's 'Click to Pray' app security flaw exposes over 700,000 users
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
A security researcher, BobDaHacker, discovered that the Vatican-linked 'Click to Pray' app had zero authentication and security, allowing anyone to access its backend via an API endpoint by simply typing user IDs. The vulnerability exposed user data including first and last names, email addresses, and birthdates. The researcher emailed nine individuals about the flaw in January 2026 but received no response for six months. The app's user IDs were sequential with no rate limiting, enabling automated data harvesting. With nearly 720,000 accounts, mostly older, less tech-savvy users, the leak posed a significant phishing risk. The issue was only fixed after security journalist Nate Nelson of Dark Reading published a story about it. The developers did not acknowledge the researcher's efforts.
Source report
A security researcher has discovered that Click To Pray, the official prayer app of the Pope’s Worldwide Prayer Network, had no security protections in place, leaving user data exposed.
Discovery and Timeline
According to a researcher using the alias BobDaHacker, the vulnerability was identified in January 2026. The Vatican-linked app allowed anyone to access user data through its API endpoint simply by entering user IDs. The researcher emailed nine individuals about the security flaws immediately upon discovery but received no response and observed no changes for six months.
Exposed Data
The information accessible from the Click To Pray app’s database included:
- First and last names
- Email addresses
- Birthdates
While this may seem limited, security experts note that names and email addresses are sufficient for bad actors to launch phishing campaigns. BobDaHacker also highlighted that the app's user base likely consists of older, less tech-savvy individuals, making them particularly vulnerable to targeted scams.
Technical Vulnerabilities
The security issues extended beyond simple API access:
- Sequential user IDs: New accounts are assigned IDs in sequence, enabling automated data harvesting.
- No rate limiting: The API allowed unlimited GET requests, making it trivial to capture the entire user database.
- Plaintext validation hash: The
validation_hashused to verify account signups was stored in clear text, allowing anyone with API access to validate accounts by simply opening an inbox. - Email security issues: Even legitimate emails from the app appeared suspicious, resembling phishing messages.
Scale of Exposure
As of July 2026, the app had approximately 720,000 accounts. While this is small compared to major data breaches (such as the 16 billion accounts exposed in one of history's largest leaks), the potential impact remains significant. If just 1% of users responded to a scammer who harvested their email addresses from the app, that would represent more than 7,000 individuals at risk of financial loss.
Resolution
After six months without a response from the app's developers, BobDaHacker contacted Nate Nelson, a security journalist at Dark Reading. Nelson published a story about the vulnerabilities after also receiving no response from the app's team. Only after the news went public were the security lapses fixed. The researcher noted they were never acknowledged by the app's makers.
It remains unclear whether any other hackers had discovered the weaknesses before the fix was applied.
Source
Latest from Tom's HardwareWestern
Part of this Story
Security flaw in Vatican's 'Click to Pray' app exposes over 700,000 users for six months