July 25, 2026

A Vatican-linked prayer app with nearly 720,000 accounts was exposed as a sitting duck, after a researcher said Click To Pray had “zero security” and let anyone pull user data just by guessing sequential IDs. The exposed API reportedly handed over names, email addresses and birthdates, an open invitation to phishing against a user base that likely skews older and less tech-savvy. The researcher says the flaws were reported in January, but after six months there was no response and no fix — leaving the Pope’s official prayer network looking more like a scammer’s jackpot than a safe place to pray.

Leave a Reply