The Pope's official prayer app leaked the personal data of over 700,000 users for months, with the Vatican offering no response to the ethical hacker who first reported the flaw.

The app, Click To Pray, is the Vatican-endorsed prayer app that attracted more than 700,000 users who are connected the global prayer network. However, Cybersecurity researcher BobDaHacker discovered a flaw in January 2026 and reported it directly to the app's operators. For six months, the bug remained unpatched, allowing anyone to access any user's data simply by altering a number in the URL. The vulnerability also let attackers register and confirm accounts using someone else's email, further increasing the risk of phishing and identity theft.
The user base, skewed toward elderly and devout Catholics, made the breach particularly dangerous. As BobDaHacker noted, "Grandma is clicking that. Every time," referencing how a bad actor could take the information from one of the elderly users and craft a phishing scam by posing as the app in some regard. The flaw was found to expose names, emails, birthdates, and locations due to a severe IDOR vulnerability, but it was quietly patched in late July 2026. However, the Vatican never acknowledged the researcher who originally discovered it, or the exposed users.

Frequently Asked Questions
TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.
When was the vulnerability patched and did the Vatican publicly acknowledge the breach?
What specific risks (for example phishing or identity theft) did researchers warn about?
Have a question not listed here? Ask below and TweakBot will answer it.
With no sign of a public response or accountability, the incident raises serious concerns about data protection in religious and institutional apps, and the lack of repercussions for violations of regulations. I suppose we can only pray that the hundreds of thousands of users that had their data exposed aren't now targeted






