Only one outlet has reported this event so far — you're reading it below, credited to its source. AIPROPX is tracking the web for more coverage; as additional outlets confirm it, this becomes a full multi-source story automatically.
By AIPROPX Editorial Desk · Published · Updated
One outlet is reporting this so far. AIPROPX is tracking it and will gather every additional source as it develops — the full multi-source comparison appears automatically once a second outlet confirms it.

On January 20, 2019, Pope Francis delivered his weekly Angelus to St Peter's Square from a window in the Vatican's Apostolic Palace. In it, he enjoined the faithful to join him on the Church's then-new Click To Pray app—helpfully modelled by a nearby priest, wielding a tablet. Hundreds of thousands of people signed up in the years that followed.
But maybe they shouldn't have, because it turns out the Click To Pray app was, until very recently, absolutely rife with info-leaking security holes. White-hat hacker BobDaHacker revealed in a July 24 blog post (via The Register ) that "The Pope's official app exposes 700,000+ user emails." The vulnerability has since been fixed, but it seems only after BobDaHacker went public with their investigation—inquiries made by the hacker and by journalists stretching back to January this year went unanswered.
The vulnerability itself was pretty simple. When you sign up for Click To Pray, the site hands your user account an ID number. The first guy to sign up was one, the next was two, and so on, all the way into the hundreds of thousands.
Problem is, by visiting https://api.clicktopray.org/user/users/[ID number goes here] , you could retrieve the name and email address, plus some other info, for whoever had the ID number you inputted. "No authorization check. No ownership validation. Just increment the number and get someone else's data. The Lord provides," writes BobDaHacker.
"Email address. First name. Last name. Country. Date of birth (or as their backend calls it, borned_date, because apparently bad grammar isn't a sacrament). Role. Whether the account has been deleted. All of it, for any user, no questions asked," they continue. "The response headers also have X-Powered-By: Express because the Vatican is running its prayer infrastructure on the framework you learn in week two of a Node.js bootcamp." I'm not smart enough to understand that, but it sounds witheringly funny.
A cherry on the parfait is that Click To Pray didn't rate limit access, meaning it would be trifling for a malicious actor to scrape the details of every single one of the app's users in the blink of an eye. As BobDaHacker points out, the kind of people who are going to be using the Pope's iPad app are likely "older, less tech-savvy, and deeply trusting of anything associated with the Vatican," which makes this data into "a phishing goldmine.
"Imagine getting an email that says 'The Holy Father requests your urgent attention' with a Vatican-looking link. Grandma is clicking that. Every time." To make matters worse, emails from the app sparked a warning that "This email has failed its domain's authentication requirements," meaning that "the real emails from Click To Pray already look like phishing."
The good news is: the problem now seems to be fixed, albeit very belatedly. "I found this in early January 2026 and on January 3rd I emailed nine people," says BobDaHacker, listing various Vatican and Click To Pray-related emails. "No response. From any of them."
It was only when BobDaHacker brought the information to a journalist and wrote their blog post that anything seemed to change. "Seven months of silence, and then, without a word to me, GET /user/users/{id} quietly stopped handing out the good stuff," they wrote. "The authorization check is there now: request your own user ID and you still get your email back, request someone else's and you get a public profile." I've even signed up for the app myself—see you there—and the email I received did not set off any alarm bells in my client. Thank god.
2026 games : All the upcoming games Best PC games : Our all-time favorites Free PC games : Freebie fest Best FPS games : Finest gunplay Best RPGs : Grand adventures Best co-op games : Better together
Indexed and credited by AIPROPX. Originating outlet: PC Gamer. Open at source →
An original, deterministic readout — composed only from the computed coverage facts on this page. No interpretation, no rating; figures only.
AIPROPX has consolidated 1 report from 1 outlet into a single canonical entry on “Vatican scrambles to patch 'phishing goldmine' app promoted by the Pope: 'Prayer infrastructure on the framework you learn in….” Every covered outlet is based in Other.
The only timestamped report came from PC Gamer (Jul 27, 2026, 15:47 UTC).
2 statements are carried by only one outlet within this set and are not echoed by the others.
Every figure above is a direct count of real published articles. AIPROPX indexes and compares the original reporting — it never rewrites, rates, or editorializes — and each publisher’s full article is always one click away.
Generated by AIPROPX from the source counts above. AIPROPX indexes and resolves coverage; the original publishers are credited and linked at origin in every report.
Coverage from 1 independent outlet across 1 region — each view opens on its own page.
AIPROPX — “Vatican scrambles to patch 'phishing goldmine' app promoted by the Pope: 'Prayer infrastructure on the framework you learn in…” · https://www.aipropx.com/story/f621994b33a1deed33bbf23c5f70a64b
Other events being covered across multiple sources right now.
Call for art: Arts Illuminated wants you for its next live art talk show
5 outletsThe Best Samsung Galaxy Z Fold 8 Cases You Can Get Today
5 outletsBlack Arts Fest MKE: What you need to know
4 outletsFramework 13 Pro review
3 outletsNvidia and OpenAI in talks for up to $250 billion dollar backstop to fund AI infrastructure plans
3 outletsThe Monday Catch-Up: Top Buffalo News stories you may have missed