Moody notices and monitoring
Keep the full breach letter, envelope, email, enrollment code, monitoring deadline, and any communications with Moody or Kroll.
Hall Attorneys is evaluating potential claims for people affected by a June 2026 Moody Bible Institute incident involving more than 2.3 million reported accounts and personal information.
affected accounts listed by HIBP
according to Moody's notice
identity, contact, address, and profile fields
Answer at a glance
Moody says its systems detected unusual network activity on June 12, 2026. Its later individual notice says a forensic review determined that information was illegally acquired from its systems on or about that date.
Have I Been Pwned attributes the incident to a ShinyHunters pay-or-leak campaign and says personal data was later published publicly. Its verified entry lists 2,303,416 unique email addresses.
This is an investigation, not a filed lawsuit. Facts may change as Moody, regulators, or security researchers publish additional information.
Moody's individual notice says its cybersecurity system detected unusual network activity and that a later forensic review determined information was illegally acquired on or about the same date.
Moody said it had implemented security protocols, engaged internal and external cybersecurity experts, notified law enforcement, and was still investigating the nature of the data involved.
Moody's notice says it identified the files acquired from its systems. Have I Been Pwned and contemporary security reporting later described personal data as publicly released.
Have I Been Pwned added a verified Moody Bible Institute entry that currently lists 2,303,416 unique email addresses and seven compromised data categories.
The California Attorney General published Moody's sample notice. It says the incident involved a vulnerability in software commonly used by educational institutions, that Moody patched the vulnerability, and that affected people were offered one year of Kroll monitoring.
Reported data categories
Have I Been Pwned lists seven types of compromised data. The information associated with a particular person may vary.
Important distinction
Have I Been Pwned does not list Social Security numbers, passwords, financial-account information, or payment-card data for this incident. Moody's offer of credit monitoring does not, by itself, establish that any particular unlisted data category was exposed.
Who may want to contact us
The investigation is focused on notice recipients and people whose identity, contact, address, or profile information may appear in the reported dataset, especially those experiencing related misuse or loss.
People who received a July 2026 Moody Bible Institute data breach notice
Current or former students and alumni whose email address appears in the reported dataset
Donors, supporters, and other people connected with Moody ministries whose information may have been involved
People experiencing Moody-themed phishing, identity misuse, suspicious account activity, fraud, or related time and expense
What to preserve
Preserve the records below, but do not send passwords, monitoring enrollment codes, complete financial-account numbers, government identification, or unredacted credit reports through ordinary website forms.
Keep the full breach letter, envelope, email, enrollment code, monitoring deadline, and any communications with Moody or Kroll.
Preserve records showing your relationship with Moody, including enrollment, alumni, donor, supporter, employment, ministry, publishing, radio, conference, or account records.
Save dated screenshots or records showing the name, email address, phone number, physical address, birth date, or profile details Moody held about you.
Keep emails, texts, calls, donation requests, account messages, or other communications that use Moody-specific details or appear to impersonate Moody.
Preserve credit alerts, unfamiliar-account notices, fraud reports, credit-freeze confirmations, identity-monitoring results, and related correspondence.
Track time spent securing accounts, monitoring credit, responding to suspicious activity, and addressing identity misuse, along with out-of-pocket costs and losses.
Investigation focus
Hall Attorneys is reviewing the reported intrusion, the software vulnerability, the data involved, Moody's response and notice process, and harms reported by affected people.
Public records reviewed
The factual statements above distinguish Moody's notices from indexed breach data and attributed security reporting. They may change as more information becomes available.
Moody Bible Institute ·
Moody's public statement confirms the incident response, external forensic assistance, law-enforcement notification, and the investigation's then-ongoing status.
Read source: Moody Bible Institute Data Incident InvestigationCalifornia Attorney General ·
Provides Moody's redacted individual notice, the June 12 breach date, the software-vulnerability description, remediation summary, and monitoring offer.
Read source: Submitted Breach Notification SampleHave I Been Pwned ·
Lists 2,303,416 affected accounts, seven compromised data categories, the reported public release, and the ShinyHunters attribution.
Read source: Moody Bible Institute Data BreachThe Register ·
Contemporary security reporting on the reported public release, affected groups, data categories, and the broader extortion campaign.
Read source: Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expertContact the firm
Contact Hall Attorneys with your name, contact information, general relationship to Moody, and a summary of the notice or suspicious activity. Do not include passwords, monitoring codes, complete financial-account numbers, Social Security numbers, or government identification in an initial message.
Common questions
No. This page describes an investigation by Hall Attorneys. It does not state that Hall Attorneys has filed a lawsuit over the Moody Bible Institute incident.
Have I Been Pwned lists 2,303,416 affected accounts, representing unique email addresses in the indexed dataset. That figure does not necessarily equal the number of distinct people, and it does not establish that every record contained every listed data category.
Have I Been Pwned lists names, dates of birth, email addresses, phone numbers, physical addresses, genders, and marital statuses. The information associated with a particular person may vary.
Moody publicly confirmed a data incident investigation on June 22, 2026. Its July 23 sample notice says information was illegally acquired from its systems on or about June 12, 2026.
Have I Been Pwned does not list Social Security numbers, passwords, financial-account information, or payment-card data among the seven compromised categories. The public sources reviewed for this page do not establish that those categories were part of the indexed dataset.
Moody's July 23 sample notice offers affected people a complimentary one-year membership in Kroll 3B Identity Monitoring, with triple-bureau credit monitoring, fraud consultation, and identity-theft restoration. The sample notice gives an October 26, 2026 enrollment deadline; recipients should follow the date and instructions in their own letter.
People may want to contact the firm if they received a Moody notice, their email appears in the reported dataset, they believe one or more listed data categories was involved, or they experienced related phishing, account misuse, identity theft, fraud, financial loss, monitoring costs, or time loss.
Preserve the complete notice, consider activating offered monitoring before the deadline in your letter, review financial and online accounts, consider fraud alerts or credit freezes, use unique passwords, and verify Moody-themed messages through a known contact method.
Attorney Advertising
Hall Attorneys is not affiliated with Moody Bible Institute, Have I Been Pwned, the California Attorney General, or Kroll. This page concerns an investigation, not a filed lawsuit. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, Social Security numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.