Skip to main content
Jump to a category page

The Archdiocese of Indianapolis has disclosed a data breach involving Social Security numbers. The organization filed notice with the Vermont Attorney General on July 28, 2026.

The Vermont filing confirms at least one Vermont resident was affected and that Social Security numbers were involved. The underlying breach date, how the incident happened, and the total number of people affected haven’t been separately disclosed in the filing.

An Early-Stage Disclosure

The Archdiocese of Indianapolis oversees parishes, schools, and Catholic Charities programs across central and southern Indiana, employing and serving many thousands of people. A single Vermont resident is very unlikely to be the full scope of this incident; it’s far more likely an early fragment of a breach that affects far more people once additional state filings or a direct notification letter surface.

What Information Was Exposed?

Per the Vermont Attorney General filing, the compromised information includes:

  • Social Security Number

No other data types have been confirmed as of this writing.

How Many People Are Affected?

At least one Vermont resident, per the state filing. No broader population figure, whether for Indiana or nationally, has been disclosed.

What Is the Archdiocese Offering?

Not publicly disclosed. No individual notification letter or credit monitoring offer has surfaced beyond the Vermont filing itself.

Your Information Is at Risk

A Social Security number on its own is enough to enable identity theft, including fraudulent new credit accounts and fraudulent tax filings. If you’ve received a letter from the Archdiocese of Indianapolis, or believe your information may have been involved, that risk is real even without additional details about how the breach happened.

Do You Have Legal Options?

Religious and nonprofit institutions that collect Social Security numbers, whether from employees, parishioners, students, or program participants, have the same legal duty to protect that information as any other organization.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

How many people were affected by the Archdiocese of Indianapolis data breach?

At least one Vermont resident, per the state’s Attorney General filing. No broader total has been disclosed, and given the size of the Archdiocese, this figure is likely just a small fragment of the true scope.

What information was exposed?

A Social Security number, per the Vermont AG filing. No other data types have been confirmed yet.

Has the Archdiocese explained how the breach happened?

Not publicly, as of this writing. The Vermont filing confirms the breach and the affected data type but doesn’t detail the cause or a discovery timeline.

What should I do if I think I’m affected?

Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion, monitor your accounts and tax filings closely, and consider speaking with a data breach attorney about your options.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now