A hacking group called ShinyHunters claims it broke into Moody Bible Institute’s computer systems in June 2026. State regulators have now confirmed the stolen files include Social Security numbers, driver’s license numbers, and birth dates for thousands of people.
Moody Bible Institute, a Chicago-based Christian college, discovered unusual activity on its network in June 2026. A group calling itself ShinyHunters posted a claim on a dark-web extortion site on June 15, 2026, saying it had stolen 23 gigabytes of data spread across more than 1,300 files. Moody Bible Institute began mailing notice letters to affected individuals on July 23, 2026, more than five weeks after the group’s public claim.
How the Breach Happened
ShinyHunters listed Moody Bible Institute on its dark-web leak site on June 15, 2026, according to independent security researchers. HaveIBeenPwned, a website that tracks stolen data, independently confirmed on July 3, 2026 that the leaked dataset contains about 2.3 million email addresses, as reported by SC Media and CyberSecurityNews. Moody Bible Institute’s own notice letter, dated July 23, 2026, says the college’s cybersecurity system flagged unusual network activity on June 12, 2026, and that files were taken from its systems around that same date.
Who ShinyHunters Is
ShinyHunters is a hacking group. Groups like this break into company networks, copy files, and then post the stolen data on hidden “dark web” websites. They often use the threat of a public leak to pressure a company into paying them. ShinyHunters has claimed credit for breaches at other organizations in the past.
What Information Was Exposed
Two different sources describe the scope of this breach, and they do not fully line up.
The dataset ShinyHunters posted, independently verified by HaveIBeenPwned, appears to contain about 2.3 million email addresses, along with names, physical addresses, and phone numbers, according to SC Media and CyberSecurityNews.
Separately, a notice filed with the Washington Attorney General on July 23, 2026 confirms that 8,955 Washington residents had more sensitive information exposed: Social Security numbers, driver’s license or state ID numbers, and full dates of birth. A California Attorney General filing, also reported July 23, 2026, confirms a California connection to the breach but does not disclose how many California residents were affected, consistent with that state’s reporting policy.
It is not yet clear whether the Social Security numbers, driver’s license numbers, and dates of birth confirmed in the Washington filing were limited to Washington residents, or whether similar data was exposed for people in the larger, 2.3-million-record dataset. Moody Bible Institute’s individual notice letters list the specific data types affected for each recipient.
Why the Notice Took Five Weeks
ShinyHunters publicly claimed the breach on June 15, 2026. Moody Bible Institute did not begin mailing notice letters to affected individuals until July 23, 2026 — more than five weeks later.
What Moody Bible Institute Is Doing
Moody Bible Institute says a vulnerability in a software application commonly used by educational institutions caused the breach. The college says it patched the vulnerability and has taken additional steps to reduce the risk of a repeat incident. Moody Bible Institute is offering affected individuals a complimentary one-year membership in Kroll’s 3-Bureau Identity Monitoring service. The enrollment deadline is October 26, 2026.
Do You Have Legal Options?
Colleges and universities that collect Social Security numbers, driver’s license numbers, and other sensitive information have a legal duty to protect it. A gap of more than five weeks between a public extortion claim and formal notice to affected individuals raises questions about whether Moody Bible Institute met that duty. Emery | Reddy, PC is investigating potential claims on behalf of additional individuals affected by this breach.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
FAQ
How many people were affected by the Moody Bible Institute data breach?
Moody Bible Institute has not confirmed one official total. A Washington regulatory filing confirms 8,955 Washington residents were affected. Separately, an independently verified leaked dataset contains about 2.3 million email addresses tied to the breach. These are two different figures from two different sources, and it is not yet clear how they relate to each other.
What information was stolen for the Washington residents confirmed in the breach?
According to the Washington Attorney General filing, the stolen files included Social Security numbers, driver’s license or state ID numbers, and full dates of birth for the 8,955 Washington residents affected.
What information was in the larger, 2.3-million-record dataset?
Independent researchers confirmed that dataset contains email addresses, names, physical addresses, and phone numbers. It has not been confirmed whether it also contains Social Security numbers or other sensitive data for everyone in it.
Is Moody Bible Institute offering identity monitoring?
Yes. Moody Bible Institute is offering a complimentary one-year membership in Kroll’s 3-Bureau Identity Monitoring service. The enrollment deadline is October 26, 2026.
Should I sign up for the monitoring if I get a letter?
Yes. It’s free, and it can alert you if someone tries to open a new account in your name. Signing up will not hurt your credit score.
What else can I do to protect myself?
Consider these steps:
- Place a fraud alert or a credit freeze with Equifax, Experian, and TransUnion
- Check your credit report for accounts you do not recognize
- Watch for phishing emails, texts, or phone calls that mention this breach by name
- Report anything suspicious to your bank, the FTC, or your state attorney general
Do I have a legal claim?
Organizations that collect Social Security numbers and other sensitive personal information have a legal duty to keep it secure. If that duty was not met, affected individuals may be entitled to compensation. Emery | Reddy offers free, no-obligation case reviews. Call 206.207.8929 or visit www.emeryreddy.com to speak with a data breach attorney.