Vatican scrambles to patch 'phishing goldmine' app promoted by the Pope: 'Prayer infrastructure on the framework you learn in week 2 of a Node.js bootcamp'

Pope Francis points to a tablet computer as he invites the faithful to download the "Click to Pray" app.
(Image credit: VINCENZO PINTO/AFP via Getty Images)

On January 20, 2019, Pope Francis delivered his weekly Angelus to St Peter's Square from a window in the Vatican's Apostolic Palace. In it, he enjoined the faithful to join him on the Church's then-new Click To Pray app—helpfully modelled by a nearby priest, wielding a tablet. Hundreds of thousands of people signed up in the years that followed.

But maybe they shouldn't have, because it turns out the Click To Pray app was, until very recently, absolutely rife with info-leaking security holes. White-hat hacker BobDaHacker revealed in a July 24 blog post (via The Register) that "The Pope's official app exposes 700,000+ user emails." The vulnerability has since been fixed, but it seems only after BobDaHacker went public with their investigation—inquiries made by the hacker and by journalists stretching back to January this year went unanswered.

The vulnerability itself was pretty simple. When you sign up for Click To Pray, the site hands your user account an ID number. The first guy to sign up was one, the next was two, and so on, all the way into the hundreds of thousands.

Latest Videos FromPC Gamer

Problem is, by visiting https://api.clicktopray.org/user/users/[ID number goes here], you could retrieve the name and email address, plus some other info, for whoever had the ID number you inputted. "No authorization check. No ownership validation. Just increment the number and get someone else's data. The Lord provides," writes BobDaHacker.

"Email address. First name. Last name. Country. Date of birth (or as their backend calls it, borned_date, because apparently bad grammar isn't a sacrament). Role. Whether the account has been deleted. All of it, for any user, no questions asked," they continue. "The response headers also have X-Powered-By: Express because the Vatican is running its prayer infrastructure on the framework you learn in week two of a Node.js bootcamp." I'm not smart enough to understand that, but it sounds witheringly funny.

A cherry on the parfait is that Click To Pray didn't rate limit access, meaning it would be trifling for a malicious actor to scrape the details of every single one of the app's users in the blink of an eye. As BobDaHacker points out, the kind of people who are going to be using the Pope's iPad app are likely "older, less tech-savvy, and deeply trusting of anything associated with the Vatican," which makes this data into "a phishing goldmine.

"Imagine getting an email that says 'The Holy Father requests your urgent attention' with a Vatican-looking link. Grandma is clicking that. Every time." To make matters worse, emails from the app sparked a warning that "This email has failed its domain's authentication requirements," meaning that "the real emails from Click To Pray already look like phishing."

The good news is: the problem now seems to be fixed, albeit very belatedly. "I found this in early January 2026 and on January 3rd I emailed nine people," says BobDaHacker, listing various Vatican and Click To Pray-related emails. "No response. From any of them."

It was only when BobDaHacker brought the information to a journalist and wrote their blog post that anything seemed to change. "Seven months of silence, and then, without a word to me, GET /user/users/{id} quietly stopped handing out the good stuff," they wrote. "The authorization check is there now: request your own user ID and you still get your email back, request someone else's and you get a public profile." I've even signed up for the app myself—see you there—and the email I received did not set off any alarm bells in my client. Thank god.

2026 gamesBest PC gamesFree PC gamesBest FPS gamesBest RPGsBest co-op games

2026 games: All the upcoming games
Best PC games: Our all-time favorites
Free PC games: Freebie fest
Best FPS games: Finest gunplay
Best RPGs: Grand adventures
Best co-op games: Better together

Joshua Wolens
News Writer

One of Josh's first memories is of playing Quake 2 on the family computer when he was much too young to be doing that, and he's been irreparably game-brained ever since. His writing has been featured in Vice, Fanbyte, and the Financial Times. He'll play pretty much anything, and has written far too much on everything from visual novels to Assassin's Creed. His most profound loves are for CRPGs, immersive sims, and any game whose ambition outstrips its budget. He thinks you're all far too mean about Deus Ex: Invisible War.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.