{"rewrite":{"id":"r_0f8e408b5c54498652de31c1","clusterId":"c_5c3a9448132b7ebc229e82ec","slug":"vatican-prayer-app-click-to-pray-leaks-700-000-user-emails","model":"deepseek-v4-flash:free","headline":"Vatican Prayer App Click to Pray Leaks 700,000 User Emails","summary":"Security researcher BobDaHacker found that the Vatican's Click to Pray app exposed all users' names and email addresses via an API endpoint. The vulnerability went unreported for over six months after being disclosed, and was only fixed after the issue was published. The app has around 720,000 accounts.","whyItMatters":"The app's user base, likely including many elderly non-tech-savvy individuals, makes the leaked email addresses a valuable target for scammers, and the developer's six-month silence raises questions about its security response.","webCardHtml":"\u003cp\u003eThe Vatican\u0026#39;s official prayer app Click to Pray had a security flaw that let anyone access user data by entering a user ID at an API endpoint. The exposed information included first and last names, email addresses, and birth dates.\u003c/p\u003e\u003cp\u003eResearcher BobDaHacker found that user IDs were sequential and the API had no rate limit, so a single GET request per user could collect the entire database. The validation_hash used to confirm account registration was stored in plain text, allowing anyone with API access to authenticate accounts. Even the emails sent by the app looked like phishing messages.\u003c/p\u003e\u003cp\u003eBobDaHacker reported the issue by email but received no response for over six months. The problem was fixed only after the story was published, and the developer never thanked or acknowledged the researcher.\u003c/p\u003e","blueskyPost":"Vatican's Click to Pray app exposed 700k+ user emails via an API flaw. Researcher reported it, got silence for 6 months, fixed only after publication. No thanks given.","twitterPost":"Vatican's Click to Pray app leaked 700k+ user emails. Researcher reported it, got silence for 6 months, fixed only after publication. No thanks given.","threadsPost":null,"newsletterBlurb":"A security researcher found that the Vatican's Click to Pray app exposed all users' names and email addresses through an API endpoint. The flaw went unreported for over six months after being disclosed, and was only fixed after the issue was published. The app has around 720,000 accounts.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260727-click-to-pray-data-leaking/\",\"title\":\"バチカンのお祈りアプリ「Click to Pray」にセキュリティ上の欠陥があり70万人以上のユーザーが危険にさらされたことが判明\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":5235,"outputTokens":568,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1786238769,"createdAt":"2026-08-09T01:20:27.000Z","publishedAt":"2026-08-09T01:21:44.000Z","updatedAt":"2026-08-09T01:20:27.000Z"},"cluster":{"id":"c_5c3a9448132b7ebc229e82ec","canonicalTitle":"バチカンのお祈りアプリ「Click to Pray」にセキュリティ上の欠陥があり70万人以上のユーザーが危険にさらされたことが判明","representativeArticleId":"a_99ec4345d8f96d04cbe575e5","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[\"Click to Pray\"],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-07-27T03:48:00.000Z","lastSeenAt":"2026-07-27T03:48:00.000Z","updatedAt":"2026-08-09T01:21:44.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260727-click-to-pray-data-leaking/","title":"バチカンのお祈りアプリ「Click to Pray」にセキュリティ上の欠陥があり70万人以上のユーザーが危険にさらされたことが判明"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":["Click to Pray"],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
