No Need to Hack When It’s Leaking: Click to Pray edition
Click to Pray, a papal-endorsed prayer app with hundreds of thousands of users globally, exposed users' names and email addresses for an extended period — potentially months or longer. An ethical hacker discovered and reported the leak.
Why this matters: People downloading a faith app are not thinking about their data footprint. They are trying to pray. That trust makes the exposure worse. Names and emails tied to a religious app can reveal something personal — belief, practice, community — that users never meant to share with anyone. No sophisticated attack was needed here. The data was just sitting out. That is not bad luck. That is a failure to do the basics, and the people who got hurt had no way to know it was happening.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.