Pope’s Official Prayer App Leaks Data of Over 700,000 Users

Click to Pray, the Vatican’s official prayer platform launched by Pope Francis himself, just got caught in a classic tech face-palm.

A security researcher going by BobDaHacker found that the app had been quietly handing over personal details — email addresses, full names, birth dates, countries, the works — to anyone who knew how to change a number in a web address. No password. No login. Nothing. Just sequential user IDs and an open door.

As of July, the platform had 719,517 registered accounts. That’s more than 700,000 real people who signed up to pray with the Pope and ended up on what the researcher called a “phishing goldmine.”

BobDaHacker first spotted the hole on January 3 and immediately emailed nine different people connected to the app and the Pope’s Worldwide Prayer Network. Radio silence. Six months later, the vulnerability was still wide open. Only after the story hit outlets like Dark Reading and The Register did the endpoint finally get locked down.

“No authorization check. No ownership validation. Just increment the number and get someone else’s data. The Lord provides,” the researcher wrote in a July 24 disclosure that landed with perfect deadpan timing.

The exposed data included emails, first and last names, countries, dates of birth (stored under the charming field name “borned_date”), account roles, and even whether an account had been deleted. Staff accounts with the lowest ID numbers were sitting right there too. To make matters worse, the signup process was leaking verification hashes, and the real emails from the service itself lacked proper authentication — meaning a fake “message from the Holy Father” could look just as legit as the real thing.

The user base made the stakes higher. A lot of people using a Vatican-endorsed prayer app are older, less tech-fluent, and more likely to trust anything that looks official. “Grandma is clicking that. Every time,” BobDaHacker noted.

After the public pressure, the sensitive fields disappeared from the API. Now third-party requests only return limited public info like names. The researcher confirmed the fix but said no one ever replied to the original reports — no acknowledgment, no thank you, nothing.

Click to Pray remains a pontifical work of the Vatican, available in seven languages on phones and the web. Neither the Pope’s Worldwide Prayer Network nor the developers at La Machi have issued a public statement.

For anyone who signed up over the years: keep an eye on your inbox. The data was sitting out there long enough that the risk of follow-up phishing isn’t theoretical. Faith may move mountains, but it apparently doesn’t always patch APIs.

Latest Posts

[democracy id="16"] [wp-shopify type="products" limit="5"]