The Moody Bible Institute of Chicago Data Breach Investigation

Data Breach Blog

Data Breach

The Moody Bible Institute of Chicago Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

July 23, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at The Moody Bible Institute of Chicago. The breach occurred on June 12th, 2026 and was discovered on an unspecified date. If you were affected, contact Almeida Law Group.

About The Moody Bible Institute of Chicago

Founded in 1886 by evangelist Dwight L. Moody, Moody Bible Institute is a private evangelical Christian higher education institution headquartered in Chicago, Illinois, at 820 North LaSalle Boulevard. It operates a college and seminary, publishes religious content through Moody Publishers, and broadcasts via Moody Radio, serving students, alumni, donors, and ministry partners across the United States and internationally. Because the institution maintains records for a large and diverse community — including students, donors, and ministry partners — a breach affecting its systems can expose a wide range of personal information tied to those relationships.

What Happened?

The Moody Bible Institute of Chicago was listed in a California Attorney General sample breach notice filed on July 23rd, 2026. According to MBI’s own breach notice, cybersecurity systems detected unusual network activity on June 12th, 2026. MBI promptly secured its systems, notified law enforcement, and engaged a forensic security firm. The institution later determined that some information was illegally acquired from its systems on or about that date, and on June 23rd, 2026, it identified the specific files that had been taken. MBI’s notice confirms the incident was caused by a vulnerability in a software application commonly used by educational institutions, which has since been patched. The notice confirms that compromised information included names and at least one additional data element, though that second element was redacted in the template letter filed with the California AG.

Independent reporting provides additional context. Threat group ShinyHunters — a data-theft and extortion group that does not typically encrypt systems — claimed responsibility via its dark-web leak site on June 15th, 2026, alleging it had exfiltrated more than 23 GB of data and setting a payment deadline of June 18th, 2026. When MBI apparently did not meet the extortion demand, ShinyHunters published the data on June 23rd, 2026. SC Media reported on July 6th, 2026 that the breach exposed data belonging to more than 2.3 million individuals. Have I Been Pwned independently confirmed that the published dataset contained approximately 2.3 million unique email addresses, with data types including names, email addresses, physical addresses, phone numbers, dates of birth, genders, and marital statuses — findings corroborated by SC Media. TechTimes reported the breach exploited CVE-2026-35273, a critical vulnerability (CVSS 9.8) in Oracle’s PeopleSoft platform, and that this incident was part of a broader ShinyHunters campaign targeting the education sector. MBI’s own notice does not explicitly name PeopleSoft or that CVE. Claims about specific data volumes and record counts — such as 46 million communication records or 108,000 biodemographic files — originate solely from ShinyHunters’ leak-site posting and have not been confirmed by MBI. As of July 2026, at least two law firms — Bryson Harris Suciu & DeMay PLLC and Ahdoot & Wolfson, PC — are investigating potential class action lawsuits, though no lawsuits had been filed as of that date.

Key Facts at a Glance

  • Company or Organization: The Moody Bible Institute of Chicago
  • Industry: Higher Education (Private, Christian/Evangelical)
  • Location: 820 North LaSalle Boulevard, Chicago, IL 60610
  • Incident type: Unauthorized access and data exfiltration; extortion by ShinyHunters threat group
  • Date of breach: June 12th, 2026
  • Date breach discovered: June 12th, 2026
  • Date of consumer notification: July 23rd, 2026
  • Total persons affected: Approximately 2.3 million (per SC Media and Have I Been Pwned; total not stated in MBI’s CA AG notice)
  • Identity theft protection offered: One-year Kroll 3B Identity Monitoring Services (complimentary)
  • Enrollment deadline: October 26th, 2026
  • Litigation status: At least two law firms investigating potential class action lawsuits; no lawsuits filed as of July 2026
  • Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-626988); SC Media (https://www.scworld.com/brief/moody-bible-institute-data-breach-exposes-2-3-million-individuals); Have I Been Pwned (https://haveibeenpwned.com/Breach/MoodyBibleInstitute); TechTimes (https://www.techtimes.com/articles/320456/20260714/moody-bible-institute-data-breach-what-23-million-donors-must-do-right-now.htm)

What Should You Do?

If you received a notice from Moody Bible Institute, enroll in the complimentary one-year Kroll 3B Identity Monitoring Services by visiting Enroll.krollmonitoring.com/redeem before the October 26th, 2026 deadline. Whether or not you received a direct notice, you should consider placing a fraud alert or credit freeze with each of the three major credit bureaus — Equifax, Experian, and TransUnion — to help prevent new accounts from being opened in your name. Review your credit reports for any unfamiliar accounts or inquiries; you can obtain free reports at AnnualCreditReport.com. Monitor your existing financial accounts for suspicious activity, and if you suspect your information has been misused, visit IdentityTheft.gov for step-by-step guidance from the Federal Trade Commission.

Your Legal Rights

If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.