The Vatican’s own prayer app accidentally leaked the data of 700,000 users online

The Vatican’s official prayer app, Click To Pray, was inadvertently leaking hundreds of thousands of user data online. While it offered users easy access to daily prayers and religious content all from their phone, it seems that it also failed to put basic cybersecurity measures in palce.
BobDaHacker, a self-described ‘ethical hacker’, found a serious vulnerability affecting the app’s API. Each user account on Click To Pray is assigned a sequential numeric user ID. However, when anyone used the API endpoint to request user data, there was no authorisation check or validation in place. This meant that anyone who supplied a valid user ID can get the email address, name, country, date of birth and account status of any user on Click To Pray.

This quickly became a serious issue when you realise that, because the user IDs are sequential, you can basically scrape the data off every user on the platform, from 1 to whatever the largest valid number is. In total, BobDaHacker found 719,517 accounts on Click To Pray, which can be accessed with a simple GET request per user.
Considering that most of the app’s users are likely going to be older users who aren’t particularly tech savvy, exposing all this data online for any hacker to easily access makes this a phishing goldmine for any bad actors. Anyone can simply check a user’s information and email them pretending to be from the app or from The Vatican.
According to BobDaHacker, they reported the issue to the Click To Pray team on 3 January 2026, emailing nine people, but got no response nor a fix to the vulnerability. Thankfully though, after making the issue public, the app has since patched the API access, and no longer gives user data out without first checking for authorisation.
Thank God.
Read more of our articles below!

