Vatican prayer app “Click to Pray” exposed 700,000 users’ data in latest breach, adding to years of cybersecurity vulnerabilities.
Newsroom (25/07/2026 Gaudium Press ) The Vatican-connected prayer application “Click to Pray,” used by hundreds of thousands of people worldwide, has exposed sensitive user information for months, marking the latest incident in a prolonged pattern of cybersecurity weaknesses tied to Vatican-affiliated platforms.
According to a report published Friday by cybersecurity news outlet Dark Reading, the app suffers from an insecure direct object reference (IDOR) vulnerability. This flaw allows unauthorized access to user data, making names and email addresses of more than 700,000 users easily accessible to anyone on the web.
“Click to Pray,” available on both iOS and Android devices, is operated by the Pope’s Worldwide Prayer Network, a pontifical society entrusted to the Society of Jesus. The organization’s mission is to support the Pope’s evangelizing efforts through prayer, offering daily prompts and a platform for users to share personal prayer intentions with a global community.
The vulnerability was first identified in January by a hacker known as “BobDaHacker,” who detailed the issue on a personal blog. Both the researcher and Dark Reading reported attempting to contact officials associated with the app and its overseeing organization, but neither received a response.
The incident underscores a broader pattern of cybersecurity challenges facing Vatican-related digital infrastructure. Over the past decade, the Vatican’s online presence has repeatedly been targeted or compromised.
Hacktivist collective Anonymous temporarily took the Vatican website offline in both 2012 and 2015, citing opposition to Church doctrine and what it described as “absurd and anachronistic concepts.” In 2022, the site experienced another disruption following Pope Francis’s criticism of Russia’s invasion of Ukraine, though responsibility for the incident was not definitively established.
Cybersecurity concerns have also intersected with geopolitical tensions. A 2020 report by threat intelligence firm Recorded Future alleged that China had attempted to infiltrate Vatican systems ahead of negotiations to renew an agreement on bishop appointments. That same year, Andrew Jenkinson, group CEO of Cybersec Innovation Partners, said he repeatedly contacted Vatican officials to warn of systemic vulnerabilities and offered assistance in addressing them.
Subsequent incidents have reinforced concerns about persistent weaknesses. In 2023, confidential documents from the Vatican’s synod on synodality were discovered on an unsecured cloud server. The following year, the Vatican’s website crashed again, with experts noting that the disruption bore hallmarks consistent with a cyberattack.
The exposure of user data through the “Click to Pray” app now adds to this growing list of incidents, raising fresh questions about the security of digital platforms tied to one of the world’s most prominent religious institutions.
- Raju Hasmukh with files from The Pillar



































