Moody Bible Institute, a Chicago-based Christian educational institution, has confirmed a significant data breach after threat actors affiliated with the ShinyHunters extortion group targeted the organization in a “pay or leak” campaign.
The incident, disclosed in June 2026, resulted in the public exposure of over 2.3 million unique email addresses along with additional personal data belonging to donors, supporters, students, and alumni.
According to Moody’s official disclosure notice, the institution’s Information Technologies Services team “immediately implemented security protocols to address the vulnerability” upon discovering the incident.
Moody Bible Institute Data Breach
Moody has since engaged both internal and external cybersecurity experts to conduct a forensic investigation and has notified law enforcement authorities, with whom it continues to cooperate.
Moody was reportedly among several colleges and universities targeted in a coordinated wave of attacks last week, suggesting the education sector remains a high-value target for extortion-focused threat actors like ShinyHunters, a group known for large-scale data theft and public leak campaigns rather than traditional ransomware encryption.
The exposed dataset reportedly includes dates of birth, email addresses, genders, marital statuses, names, phone numbers, and physical addresses belonging to donors, supporters, students, and alumni connected to the institute.
Moody has stated that the full scope of the compromised data is still under investigation, and the institution has not yet confirmed the exact attack vector or whether the ShinyHunters’ claims align precisely with its internal findings.
The breadth of personal details involved, spanning both identity and demographic information, raises concerns about downstream risks, including social engineering, targeted phishing, and identity fraud.
Moody’s executive leadership, including President Dr. Mark Jobe and General Counsel Janet A. Stiven, issued a statement emphasizing transparency and urgency while acknowledging that the investigation “remains ongoing with many details we are still working to understand.”
HIBP stated that the institution has committed to directly notifying affected individuals if forensic analysis confirms specific impact, in compliance with applicable breach notification laws.
Moody’s leadership framed the response as an institutional priority, noting that both internal IT staff and outside cybersecurity experts are working to determine the full scope of the incident before releasing further details publicly.
Security experts and Moody’s own advisory recommend that potentially affected individuals closely monitor their financial and online account statements for unauthorized activity and promptly report any suspicious transactions to the relevant institutions.
Individuals are also encouraged to place credit freezes and fraud alerts with the major credit bureaus, use strong, unique passwords across all online accounts, ideally through a password manager, and stay alert to phishing attempts that may exploit leaked personal details.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.