Investigation · Education & Donor Data

Moody Bible Institute Data Breach Investigation

Hall Attorneys is evaluating potential claims for people affected by a June 2026 Moody Bible Institute incident involving more than 2.3 million reported accounts and personal information.

Reported scale
2,303,416

affected accounts listed by HIBP

Reported acquisition date
June 12, 2026

according to Moody's notice

Data types listed
7

identity, contact, address, and profile fields

Answer at a glance

What happened in the Moody Bible Institute data breach?

Moody says its systems detected unusual network activity on June 12, 2026. Its later individual notice says a forensic review determined that information was illegally acquired from its systems on or about that date.

Have I Been Pwned attributes the incident to a ShinyHunters pay-or-leak campaign and says personal data was later published publicly. Its verified entry lists 2,303,416 unique email addresses.

This is an investigation, not a filed lawsuit. Facts may change as Moody, regulators, or security researchers publish additional information.

  1. Network alert and reported acquisition

    Moody's individual notice says its cybersecurity system detected unusual network activity and that a later forensic review determined information was illegally acquired on or about the same date.

  2. Moody publishes an incident statement

    Moody said it had implemented security protocols, engaged internal and external cybersecurity experts, notified law enforcement, and was still investigating the nature of the data involved.

  3. Acquired files identified

    Moody's notice says it identified the files acquired from its systems. Have I Been Pwned and contemporary security reporting later described personal data as publicly released.

  4. Dataset added to Have I Been Pwned

    Have I Been Pwned added a verified Moody Bible Institute entry that currently lists 2,303,416 unique email addresses and seven compromised data categories.

  5. Individual notice submitted in California

    The California Attorney General published Moody's sample notice. It says the incident involved a vulnerability in software commonly used by educational institutions, that Moody patched the vulnerability, and that affected people were offered one year of Kroll monitoring.

Reported data categories

What information was exposed?

Have I Been Pwned lists seven types of compromised data. The information associated with a particular person may vary.

Important distinction

Have I Been Pwned does not list Social Security numbers, passwords, financial-account information, or payment-card data for this incident. Moody's offer of credit monitoring does not, by itself, establish that any particular unlisted data category was exposed.

Identity details
Names and dates of birth
Contact information
Email addresses and phone numbers
Location information
Physical addresses
Personal profile details
Genders and marital statuses

Who may want to contact us

People connected with Moody

The investigation is focused on notice recipients and people whose identity, contact, address, or profile information may appear in the reported dataset, especially those experiencing related misuse or loss.

People who received a July 2026 Moody Bible Institute data breach notice

Current or former students and alumni whose email address appears in the reported dataset

Donors, supporters, and other people connected with Moody ministries whose information may have been involved

People experiencing Moody-themed phishing, identity misuse, suspicious account activity, fraud, or related time and expense

What to preserve

Keep notices, relationship records, and monitoring results

Preserve the records below, but do not send passwords, monitoring enrollment codes, complete financial-account numbers, government identification, or unredacted credit reports through ordinary website forms.

Moody notices and monitoring

Keep the full breach letter, envelope, email, enrollment code, monitoring deadline, and any communications with Moody or Kroll.

Relationship records

Preserve records showing your relationship with Moody, including enrollment, alumni, donor, supporter, employment, ministry, publishing, radio, conference, or account records.

Profile and contact records

Save dated screenshots or records showing the name, email address, phone number, physical address, birth date, or profile details Moody held about you.

Suspicious communications

Keep emails, texts, calls, donation requests, account messages, or other communications that use Moody-specific details or appear to impersonate Moody.

Credit and identity records

Preserve credit alerts, unfamiliar-account notices, fraud reports, credit-freeze confirmations, identity-monitoring results, and related correspondence.

Time, expenses, and harm

Track time spent securing accounts, monitoring credit, responding to suspicious activity, and addressing identity misuse, along with out-of-pocket costs and losses.

Investigation focus

Issues under review

Hall Attorneys is reviewing the reported intrusion, the software vulnerability, the data involved, Moody's response and notice process, and harms reported by affected people.

  1. Which educational software application and vulnerability were involved, and when the vulnerability became known or patchable
  2. How the attacker accessed Moody systems and which files were acquired
  3. How many distinct United States residents and residents of each state were affected
  4. Which of the seven reported data categories were associated with each person
  5. Whether additional information beyond the categories listed by Have I Been Pwned was involved
  6. When Moody completed its review of affected files and how it determined whom to notify
  7. Whether affected people experienced targeted phishing, account misuse, identity theft, fraud, financial loss, monitoring costs, or time loss

Public records reviewed

Sources for the Moody incident

The factual statements above distinguish Moody's notices from indexed breach data and attributed security reporting. They may change as more information becomes available.

Moody Bible Institute ·

Moody Bible Institute Data Incident Investigation

Moody's public statement confirms the incident response, external forensic assistance, law-enforcement notification, and the investigation's then-ongoing status.

Read source: Moody Bible Institute Data Incident Investigation

California Attorney General ·

Submitted Breach Notification Sample

Provides Moody's redacted individual notice, the June 12 breach date, the software-vulnerability description, remediation summary, and monitoring offer.

Read source: Submitted Breach Notification Sample

Have I Been Pwned ·

Moody Bible Institute Data Breach

Lists 2,303,416 affected accounts, seven compromised data categories, the reported public release, and the ShinyHunters attribution.

Read source: Moody Bible Institute Data Breach

Contact the firm

Did you receive a Moody breach notice?

Contact Hall Attorneys with your name, contact information, general relationship to Moody, and a summary of the notice or suspicious activity. Do not include passwords, monitoring codes, complete financial-account numbers, Social Security numbers, or government identification in an initial message.

Contact Hall Attorneys

Common questions

Moody Bible Institute data breach FAQ

Is this a filed Moody Bible Institute lawsuit?

No. This page describes an investigation by Hall Attorneys. It does not state that Hall Attorneys has filed a lawsuit over the Moody Bible Institute incident.

How many Moody Bible Institute accounts may be affected?

Have I Been Pwned lists 2,303,416 affected accounts, representing unique email addresses in the indexed dataset. That figure does not necessarily equal the number of distinct people, and it does not establish that every record contained every listed data category.

What information was reportedly exposed?

Have I Been Pwned lists names, dates of birth, email addresses, phone numbers, physical addresses, genders, and marital statuses. The information associated with a particular person may vary.

Did Moody Bible Institute confirm the breach?

Moody publicly confirmed a data incident investigation on June 22, 2026. Its July 23 sample notice says information was illegally acquired from its systems on or about June 12, 2026.

Were Social Security numbers, passwords, or payment data exposed?

Have I Been Pwned does not list Social Security numbers, passwords, financial-account information, or payment-card data among the seven compromised categories. The public sources reviewed for this page do not establish that those categories were part of the indexed dataset.

What protection did Moody offer?

Moody's July 23 sample notice offers affected people a complimentary one-year membership in Kroll 3B Identity Monitoring, with triple-bureau credit monitoring, fraud consultation, and identity-theft restoration. The sample notice gives an October 26, 2026 enrollment deadline; recipients should follow the date and instructions in their own letter.

Who may want to contact Hall Attorneys?

People may want to contact the firm if they received a Moody notice, their email appears in the reported dataset, they believe one or more listed data categories was involved, or they experienced related phishing, account misuse, identity theft, fraud, financial loss, monitoring costs, or time loss.

What should I do after the Moody Bible Institute breach?

Preserve the complete notice, consider activating offered monitoring before the deadline in your letter, review financial and online accounts, consider fraud alerts or credit freezes, use unique passwords, and verify Moody-themed messages through a known contact method.

Attorney Advertising

Hall Attorneys is not affiliated with Moody Bible Institute, Have I Been Pwned, the California Attorney General, or Kroll. This page concerns an investigation, not a filed lawsuit. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, Social Security numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.