Pope's Prayer App Leaks 700K+ Users' Data: Security Flaw Exposed

A security researcher found Click To Pray app leaking 700K+ user emails and names via an IDOR bug. No response from Vatican after 6 months. Read more.

sábado, 25 de julio de 2026 • 3 min read • Q2BSTUDIO Team

Vulnerabilidad IDOR expone correos y nombres en Click To Pray

Recently, the prayer app Click To Pray, endorsed by the Vatican and the Pope, has become the center of a security controversy exposing the personal data of over 700,000 users worldwide. An ethical hacker, known as BobDaHacker, discovered an Insecure Direct Object Reference (IDOR) vulnerability that allows unauthorized access to names, email addresses, countries, and birth dates of any registered user. Alarming is that she reported the flaw six months ago and never received a response. This case highlights how even organizations with high reputations can neglect basic cybersecurity, turning their platforms into easy targets for phishing attacks and identity theft.

The vulnerability lies in the Click To Pray API using sequential numeric user IDs without implementing any ownership control. When requesting data for a valid ID, the server returns the information without verifying if the requester has permission. This allows any attacker to enumerate all accounts simply by incrementing the number. Additionally, the registration endpoint returns a validation hash that enables account verification without needing access to the email, adding another layer of risk. The massive exposure of email addresses, especially among older and trusting church users, represents a goldmine for tailored phishing campaigns. A fake message with Vatican-like appearance could easily deceive those who place their faith in the institution.

From a technical perspective, this incident underlines the need to integrate security throughout the entire software development lifecycle. IDOR vulnerabilities are extremely common but easy to prevent through robust authentication and authorization. For companies and organizations developing applications with sensitive data, conducting regular security audits is critical. This is where companies like Q2BSTUDIO, specialized in cybersecurity and custom software development, can make a difference. Implementing good practices from the design phase, such as role-based access controls and validation of each request, would prevent personal data from being exposed.

Beyond the technical flaw, the case reveals a lack of institutional response that worsens the problem. The hacker reported the finding unsuccessfully, showing that vulnerability management depends not only on detecting flaws but also on having effective communication channels and trained teams to react quickly. In this regard, Q2BSTUDIO offers cybersecurity consulting services including code analysis, penetration testing, and incident response process establishment. Organizations that handle user data, especially those with a vulnerable user base, must prioritize information protection as part of their mission.

The impact of this leak goes beyond the technical; it affects the trust of the faithful in an institution representing values of privacy and security. To mitigate these risks, companies can adopt secure cloud platforms like AWS or Azure, which implement multiple protection layers. Q2BSTUDIO, with experience in cloud services AWS/Azure, helps design architectures that meet security standards, besides integrating artificial intelligence to detect anomalous behaviors in real time. AI agents can monitor network traffic and alert about user enumeration attempts, something that would have been useful in this case.

The lesson is clear: custom application development must include security as a functional requirement, not as an afterthought. Companies like Q2BSTUDIO offer comprehensive solutions covering everything from secure software design to implementing Business Intelligence (BI) systems with Power BI to monitor security and performance metrics. In a world where personal data is the most valuable asset, investing in cybersecurity is not optional but an ethical and business obligation. The Click To Pray leak should serve as a warning for all organizations, regardless of size or purpose, that security is not a luxury but a fundamental necessity.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.