Last updated 2 weeks ago
Moody Bible Institute, a private Christian college in the United States, suffered a data breach disclosed in July 2026. The incident involved the exposure of over 2.3 million unique email addresses and associated personal data. The breach was discovered after ShinyHunters launched a 'pay or leak' extortion campaign in June 2026, and the data was subsequently published publicly.
The attack vector was unauthorized access, with ShinyHunters exfiltrating a database containing names, physical addresses, phone numbers, dates of birth, and other information related to donors, supporters, students, and alumni. The specific initial access method was not disclosed, but the threat actor group ShinyHunters is known for extortion-driven breaches. The compromised data types include personally identifiable information (PII) that could enable identity theft or targeted phishing.
Moody Bible Institute engaged internal and external cybersecurity experts to investigate the incident. No regulatory actions, litigation, or ransom payment details have been reported as of the disclosure date. The breach notification status is confirmed via public disclosure.
Extortion campaign by ShinyHunters, data later published publicly
Moody Bible Institute's breach underscores the need for educational institutions to implement robust access controls and monitoring for donor and alumni databases. The exfiltration of over 2.3 million records suggests inadequate network segmentation and insufficient detection of large-scale data transfers. Organizations in the education sector should prioritize encryption of sensitive PII at rest and enforce multi-factor authentication for database access to mitigate similar extortion-driven attacks.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor