Vatican Prayer App Security Flaw May Have Exposed Nearly 720,000 Users

A security researcher has reported that a vulnerability in the Vatican’s Click To Pray mobile application may have exposed the personal information of hundreds of thousands of registered users, prompting concerns about potential phishing attacks targeting Catholics.

According to Straight Arrow News, independent security researcher “BobDaHacker” disclosed that the issue has allegedly remained unresolved for at least six months despite multiple attempts to notify those responsible for the app.

Click To Pray, launched in 2019 by the Pope’s Worldwide Prayer Network, is described as “a digital community of prayer where you can share the intentions of the Holy Father and pray together with others.” The app allows Catholics around the world to unite in prayer with the Holy Father’s monthly intentions and to share their own prayer requests.

According to the researcher, approximately 719,517 registered user accounts were affected as of July. The exposed information reportedly includes users’ names, email addresses, and countries of origin.

In a blog post published Friday, the researcher said they contacted nine email addresses associated with the application on Jan. 3 to report the vulnerability but never received a response.

“The vulnerability is still live,” the researcher wrote. “Nobody has ever responded. I guess my email wasn’t in their prayers.”

According to Straight Arrow News, the reported flaw is an insecure direct object reference (IDOR), a type of web application vulnerability that can allow unauthorized users to access information simply by modifying a numerical identifier in a website address.

Describing how the issue worked, the researcher wrote, “One of the most basic access control flaws in web security. You ask for your own data, the server gives it to you. You ask for someone else’s data, the server gives you that too.”

Straight Arrow News reported that it independently tested the application after the researcher disclosed the credentials used during testing and was able to confirm the reported vulnerability.

According to Straight Arrow News, neither the Pope’s Worldwide Prayer Network nor the cybersecurity publication Dark Reading received a response to requests for comment regarding the reported security issue.

The researcher also warned that the exposed information could be valuable to cybercriminals attempting to deceive faithful Catholics through convincing phishing campaigns.

“That’s 700,000+ email addresses belonging to people who signed up for an app to pray,” the researcher wrote. “A lot of these users are likely older, less tech-savvy, and deeply trusting of anything associated with the Vatican.”

The researcher continued by cautioning, “A harvested list like this would be a phishing goldmine. Imagine getting an email that says ‘The Holy Father requests your urgent attention’ with a Vatican-looking link. Grandma is clicking that. Every time.”

As of the publication of Straight Arrow News’ report, the vulnerability was still said to be active. Users of Click To Pray are encouraged to remain vigilant against unsolicited emails claiming to originate from the Vatican or Church organizations and to verify the authenticity of any requests before clicking links or providing personal information.


Your support brings the truth to the world.

Catholic Online News exists because of donors like you. We are 100% funded by people who believe the world deserves real, uncensored news rooted in faith and truth — not corporate agendas. Your gift ensures millions can continue to access the news they can trust — stories that defend life, faith, family, and freedom.

When truth is silenced, your support speaks louder.

Leave a Reply

Your email address will not be published. Required fields are marked *