Blog > Data Breach & Privacy

Moody Bible Institute Data Breach: What Affected Individuals Need to Know

The Moody Bible Institute of Chicago has confirmed a data breach after a ShinyHunters extortion campaign led to the public exposure of personal data belonging to donors, supporters, students, and alumni. If you are affiliated with Moody, here is what is known and what you can do.

Source note: Moody issued an official disclosure notice, and the exposure of over 2.3 million unique email addresses along with names, addresses, phone numbers, dates of birth, genders, and marital statuses has been catalogued by the breach-notification service Have I Been Pwned. Larger record-count figures (such as “tens of millions” of records) originate from the threat actor’s own claims and have not been independently verified. This article distinguishes confirmed facts from unverified claims.

Moody Bible Institute Data Breach: What Affected Individuals Need to Know

What Happened in the Moody Bible Institute Data Breach

An extortion campaign targeting a Chicago institution

Moody Bible Institute is a Chicago-based Christian educational institution. In June 2026, threat actors affiliated with the ShinyHunters extortion group targeted the organization in a “pay or leak” campaign. According to Moody’s official disclosure, the institution’s Information Technologies Services team implemented security protocols to address the vulnerability upon discovering the incident, and Moody engaged both internal and external cybersecurity experts to conduct a forensic investigation and notified law enforcement.

The incident was disclosed in June 2026, and it resulted in the public exposure of personal data. ShinyHunters is a data-theft and extortion group known for large-scale data theft and public leak campaigns rather than traditional ransomware encryption. Moody was reportedly among several educational institutions targeted in a coordinated wave of attacks.

What Information Was Exposed in the Breach

The confirmed categories of exposed data

According to the exposure catalogued by Have I Been Pwned, over 2.3 million unique email addresses were published publicly, along with names, physical addresses, phone numbers, dates of birth, genders, marital statuses, and other information relating to donors, supporters, students, and alumni. Moody advised in its disclosure notice that it had engaged internal and external cybersecurity experts to investigate the matter.

The threat actor made broader claims about the volume and nature of the stolen data, including figures in the tens of millions of records. Those figures come from the attacker and have not been independently verified. The confirmed, publicly documented exposure centers on the contact and biographical details described above, which — while not always sufficient on their own to enable financial fraud — can fuel targeted phishing and scams.

Who Is Affected and Why It Matters

Understanding your exposure

Because the exposed data relates to donors, supporters, students, and alumni, affected individuals span a wide community connected to Moody Bible Institute. Anyone whose email address, name, address, phone number, or date of birth was in Moody’s systems may be affected.

When contact details and dates of birth are exposed in a public leak, a primary risk is targeted phishing — messages crafted to look legitimate because they reference accurate personal details. Remaining skeptical of unexpected communications that reference Moody or your personal information is an important protective habit.

Steps to Take If You Were Affected

Practical protective steps

Be especially alert to phishing emails, calls, and texts that reference Moody Bible Institute or your personal details, and avoid clicking links or sharing information in response to unsolicited messages. Consider using a password manager and enabling multi-factor authentication on your important accounts, particularly if you reused any password associated with an exposed email address.

Monitor your financial and institutional accounts for unauthorized activity, and consider enrolling in identity monitoring or credit protection services if they are offered. If you receive a direct notification from Moody, keep it and follow its instructions. A legal professional can help you understand whether you may have legal options.

Readers following similar incidents can also see our overview of the MBE CPAs data breach lawsuit.

FAQs

The incident was disclosed in June 2026 following a ShinyHunters "pay or leak" extortion campaign against the institution.

Publicly documented exposure includes over 2.3 million unique email addresses, along with names, physical addresses, phone numbers, dates of birth, genders, and marital statuses relating to donors, supporters, students, and alumni.

Over 2.3 million unique email addresses were publicly exposed. Larger figures claimed by the threat actor have not been independently verified.

Threat actors affiliated with the ShinyHunters extortion group targeted Moody in a "pay or leak" campaign, according to reporting and Moody's disclosure.

Because contact details and dates of birth were exposed, a primary risk is targeted phishing. Be cautious of unexpected messages referencing Moody or your personal information.

You may have legal options if your information was exposed. A legal professional can review your situation during a free consultation.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,521 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance