Skip to content
logo The magazine for digital lifestyle and entertainment
CoBi Data protection News Security All topics
Data Privacy Breach

Oh God! Vatican App Exposed User Data Online

The ClickToPray app had significant security vulnerabilities.
The Vatican app "Click to Pray" had serious security vulnerabilities that put user data at risk. Photo: Getty Images
Share article

July 30, 2026, 1:33 pm | Read time: 2 minutes

Ironically, the Vatican’s official prayer app has been flagged for serious security vulnerabilities. According to a security researcher using the pseudonym “BobDaHacker,” personal data of more than 719,000 registered users could be accessed relatively easily.

According to a blog post, the affected app was “Click to Pray”, available for Android, iPhone, and as a web app. Through the service, believers can share their prayer intentions and join the pope’s worldwide prayer network.

Simple User IDs Made Data Accessible

The cause of the data breach was reportedly an unprotected API endpoint. According to the researcher, access only required entering a user ID. Since the system assigned these IDs sequentially, data sets could be queried automatically. This made names, email addresses, birth dates, countries of origin, and account status information accessible. For attackers, this posed little challenge.

In addition to the database vulnerability, the expert discovered another issue in the registration process. Although the service sent verification emails, the necessary information for account activation could be retrieved beforehand via an API. This theoretically allowed user accounts to be activated and taken over with foreign email addresses. This is particularly critical because such a vulnerability can facilitate targeted attacks on individual accounts.

Also of interest: How risky is online banking on a smartphone

Response Came Only After Months

According to BobDaHacker, the vulnerabilities were reported to the operators on January 3, 2026. A response was reportedly not received for several months. It was only after the IT portal Dark Reading reported on the incident at the end of July that the security issues were said to have been resolved. Whether the vulnerabilities were actively exploited in the meantime is currently unknown.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.