Vatican’s Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw
The Vatican’s Click to Pray app reportedly exposed the personal information of more than 700,000 users because account details could be accessed online without logging in. People who created an account on the app or website may have had their information viewed by others.
Who is at risk
Anyone who has used the Click to Pray app or website and created an account is most at risk.
What to watch for
Watch for unexpected emails, messages, or account activity that uses your name or references your involvement with the app.
What to do
If you use Click to Pray, change your password immediately, avoid reusing that password anywhere else, and be extra cautious with unexpected messages asking for personal information.
