The Vatican A.I CyberSecurity Scoring
The Vatican
Company Information
Website:https://www.vaticanstate.va/it/
Employees number:411
Number of followers:0
NAICS:92
Industry Type:Government Administration
Homepage:vaticanstate.va
The Vatican Risk Score (AI oriented)
Between 750 and 799
The VaticanGovernment Administration
Updated:
27/07/2026
27/07/2026
787/1000
Fair
Baa
The Vatican Global Score (TPRM)
xxxx
The VaticanGovernment Administration
Score locked

The VaticanFair
Current Score
787Baa (FAIR)
01000
1 incidents
-49 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
836
Breach
24 Jul 2026 • The Vatican
Vatican: Vatican's Pope-Promoted Prayer App Was a Phishing Goldmine
Vatican’s Click To Pray App Exposed 700,000 Users’ Data Due to Basic API Flaw
787
CRITICAL-49
VAT1785184303
Vatican’s Click To Pray App Exposed 700,000 Users’ Data Due to Basic API Flaw
In a stark example of avoidable security failures, the Vatican’s Click To Pray app personally endorsed by Pope Francis in 2019 leaked the personal data of over 700,000 users for months due to an elementary API vulnerability. The flaw, discovered by white-hat hacker BobDaHacker in January 2026, was only patched on July 24, 2026, after seven months of unanswered disclosure attempts.
The issue stemmed from a sequential user ID system in the app’s backend API. By simply incrementing a numeric ID in the endpoint `https://api.clicktopray.org/user/users/[ID]`, anyone could access full user profiles including names, email addresses, dates of birth, countries, and account roles without authentication. The server, running on the basic Express Node.js framework, lacked rate limiting, allowing automated scraping of the entire dataset.
Despite multiple emails to Vatican and app contacts, the vulnerability remained unaddressed until BobDaHacker went public. The fix, implemented silently after the disclosure, now restricts access to a user’s own data while exposing only public-facing details for others. Notably, legitimate app emails had also triggered phishing warnings in mail clients, further eroding user trust.
The exposed data posed significant risks, particularly for the app’s predominantly older, less tech-savvy user base. With verified names, emails, and ties to a high-trust religious institution, attackers could craft highly convincing phishing campaigns. The incident underscores how even basic oversights like a missing authentication check can lead to large-scale breaches, especially when compounded by delayed responses from institutions.
The Click To Pray app remains available, with user data now secured behind the authorization controls that should have been in place from the start. The case serves as a reminder of the consequences when foundational security practices are overlooked.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
836
MAY 2026
836
APRIL 2026
836
MARCH 2026
836
FEBRUARY 2026
836
JANUARY 2026
836
DECEMBER 2025
836
NOVEMBER 2025
836
OCTOBER 2025
836
SEPTEMBER 2025
836
AUGUST 2025
836
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for The Vatican ??
What was The Vatican's A.I Rankiteo Cyber Score in June 2026 ??
What was The Vatican's A.I Rankiteo Cyber Score in May 2026 ??
What was The Vatican's A.I Rankiteo Cyber Score in April 2026 ??
What was The Vatican's A.I Rankiteo Cyber Score in March 2026 ??
What was The Vatican's A.I Rankiteo Cyber Score in February 2026 ??
What was The Vatican's A.I Rankiteo Cyber Score in January 2026 ??
What was The Vatican's A.I Rankiteo Cyber Score in December 2025 ??
What was The Vatican's A.I Rankiteo Cyber Score in November 2025 ??
What was The Vatican's A.I Rankiteo Cyber Score in October 2025 ??
What was The Vatican's A.I Rankiteo Cyber Score in September 2025 ??
What was The Vatican's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on The Vatican's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with The Vatican ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view The Vatican's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?