Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months – or longer – according to an ethical hacker who said she found and reported the security vulnerability six months ago to no avail. This app needs to take a vow of silence when it comes to your personal information.
The app, available in seven languages and on iOS, Android, and clicktopray.org, is the official app of the Pope’s Worldwide Prayer Network. It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts.
It’s also very leaky, according to security sleuth BobDaHacker, who says she spotted and disclosed the vulnerability to the Pope’s Worldwide Prayer Network on January 3.
Read more…
Source: The Register
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Uber Freight reportedly investigating after hacking group claims data breach
August 12, 2026
A hacking and extortion gang has taken credit for a cyberattack and data breach at Uber Freight, the ridesharing giant’s logistics subsidiary. A spokesperson for Uber Freight told Reuters, which first reported the incident, that there was no effect on its business operations and that its systems were running normally. (The company did not immediately respond to ...
- The CEVA Logistics data breach is having major knock-on effects across Europe – here’s what we know
August 11, 2026
CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves. CEVA has ...
- Attackers pick Levi’s pockets in social engineering attack
August 10, 2026
Levi Strauss is investigating a data breach after attackers used social engineering to access three employees’ work computers. In a regulatory filing, the jeans maker said the intruders accessed and exfiltrated what it described only as “certain corporate information.” Levi’s said it spotted the intrusion, kicked off its incident response procedures, brought in outside cybersecurity experts, and managed ...
- Intrusion at US healthcare software provider puts 3.8M people’s data at risk
August 7, 2026
A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year. The attack dates to last October, when Ohio-based medical software maker Unlimited Technology Systems (UTS) detected someone poking around its commercial datacenter. ...
- Over 100,000 UK Police and staff have personal data leaked in attack on national database
August 4, 2026
The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals. In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and ...
- OpenAI explains how its AI agent breached Hugging Face
July 29, 2026
On July 28, OpenAI published an update on the agent that escaped its sandbox and hacked into Hugging Face during an internal cybersecurity evaluation. In the update, OpenAI reiterates that the “rogue” system was a more capable, pre‑release research model, not something intended for public deployment, and that it has now been deactivated and locked down for restricted research ...

