Moody Bible Institute Data Breach Affects 2.3 Million People — Here’s What Happened

Moody Bible Institute Data Breach Affects 2.3 Million People — Here’s What Happened

You are currently viewing Moody Bible Institute Data Breach Affects 2.3 Million People — Here’s What Happened
Personal information linked to Moody Bible Institute donors, students, supporters, and alumni was published after a cyberattack affecting 2.3 million accounts.

A Moody Bible Institute data breach exposed personal details tied to 2.3 million people. Here’s what was taken, who may be affected, and how you can protect yourself online today.

What Happened?

According to Cyber Security News, personal information linked to more than 2.3 million accounts was published after a Moody Bible Institute cyberattack.

The institute discussed the incident on June 22, 2026, saying criminals claimed to have entered certain internal systems. Moody then hired internal and outside cybersecurity experts, while its technology team addressed the security weakness.

ShinyHunters published the stolen files on June 23, and Have I Been Pwned added the breach to its database on July 3. Have I Been Pwned is a service that lets people check whether their email address appeared in known data breaches.

According to Have I Been Pwned, the group used a “pay or leak” campaign, which involves stealing information, demanding money, and threatening to publish the files if payment is refused.

The published files included personal and contact details that criminals could use to make fake emails or calls seem more convincing. Information from data breaches or data leaks can resurface months or years later, and many people do not realize their data was exposed until suspicious activity appears.

If you are unsure whether your information was leaked, automatic monitoring can help you spot problems sooner. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Data Was Leaked?

The breach involved donors, supporters, students, and alumni connected to Moody Bible Institute. Have I Been Pwned lists 2.3 million affected accounts based on unique email addresses. That figure may not equal the exact number of individuals.

The confirmed data included:

  • Full names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Dates of birth
  • Genders
  • Marital statuses

Have I Been Pwned’s published list does not mention passwords, Social Security numbers, or financial account details. However, the leaked personal details could still help criminals create convincing phishing emails, impersonate Moody, or attempt identity theft.

How Criminals Entered Moody’s Systems Remains Unclear

Moody has not publicly explained how criminals entered its systems. The institute said its technology team fixed a vulnerability but did not identify it or explain how it was used.

The “pay or leak” campaign describes the extortion that followed the data theft, not how the attackers first gained access.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

Why These Personal Details Can Make Fraud More Convincing

The leaked records can help criminals build a detailed picture of you. They may know your name, address, age, and connection to Moody. A fake message could mention a past donation, student record, or alumni relationship. Those details can make an unexpected request seem legitimate.

Criminals may use these details to request payment, login codes, or more personal information while pretending to represent Moody or another trusted organization. Even without confirmed passwords or Social Security numbers, the data still deserves attention because personal details may circulate for years.

Person using a laptop to review account security after the Moody Bible Institute data breach.
After the Moody Bible Institute data breach, donors, students, supporters, and alumni should watch for suspicious messages and strengthen their account security.

5 Simple Steps to Protect Yourself After the Moody Data Breach

You cannot control every organization that stores your information. However, these simple steps can help reduce your risk:

1. Watch for messages mentioning Moody

Be careful with emails, texts, or calls about donations, student records, alumni services, or a security problem. Criminals may use leaked details to make the message sound real.

Do not click links or call numbers included in an unexpected message. Instead, visit Moody Bible Institute’s official website and use the contact information listed there to verify the request.

2. Protect your main email account

Watch for login alerts or password reset messages you did not request. Your email connects to many other services, so someone with access may reset passwords and enter your other accounts. 

Open your email settings and choose Security. Review recent sign-ins, create a strong unique password, and turn on two-step verification. This feature requires a second code when you sign in, which can block access if your password is stolen.

3. Review your financial activity

Look for small charges, withdrawals, or account changes you do not recognize. Criminals sometimes test stolen information with small transactions before attempting larger fraud. 

Review your bank and credit card statements each week. If you notice suspicious activity, contact the financial company immediately using the number on your card or its official website.

4. Consider freezing your credit

Watch for unfamiliar credit accounts, bills, or collection notices in your name. A credit freeze makes it harder for criminals to open new accounts using your information. The FTC says credit freezes are free and do not affect your credit score. 

Contact all three credit bureaus separately to freeze your credit:

Save the account details needed to lift each freeze later.

5. Follow official updates from Moody

Be careful with breach notices sent from unknown email addresses. Scammers may imitate Moody, offer fake support, or ask you to confirm personal information. 

Type Moody Bible Institute’s website address directly into your browser. Then check its official data incident page for new instructions, updates, or support information.

A Trusted Organization Can Still Lose Your Information

You may have shared your personal details with Moody as a student, alumnus, donor, or supporter. However, this breach shows that personal information can still be stolen even when you follow safe habits.

Watch for personalized messages, protect your email, and review your financial activity regularly. Tools like Futureproof can also help you spot data leaks sooner, so you can respond faster and feel more confident about your online safety.