[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3dj7mvi2sj1r4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":38,"seoTitle":39,"seoDescription":40,"logoUrl":41,"isVerified":4,"isSensitive":4,"isSpamList":42,"isMalware":42,"company":43},"6a452defa33e85be57ce5f47","Moody Bible Institute","Moody Bible Institute Data Breach","moody-bible-institute","moody.edu","2026-06-15T00:00:00.000Z","2026-07-03T16:03:25.000Z",null,"2026-07-19T00:03:51.214Z","Religious education data breach","https:\u002F\u002Fwww.moodybible.org\u002Fnews\u002F2026\u002Fdata-investigation\u002F",[16,18,19],"https:\u002F\u002Fcyberinsider.com\u002Fmoody-bible-institute-investigates-potential-data-breach-incident\u002F","https:\u002F\u002Fwww.theregister.com\u002Fsecurity\u002F2026\u002F07\u002F06\u002Fmoody-bible-institute-breach-leaves-23m-accounts-needing-salvation-says-cyber-expert\u002F5266827",2303416,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Critical",[31,32,33,34,35,36,37],"Dates of birth","Email addresses","Genders","Marital statuses","Names","Phone numbers","Physical addresses","\u003Cp>The Moody Bible Institute data breach is a confirmed 2026 security incident related to the Chicago-based religious education institution, publishing, and donor relations network. The record is dated June 15, 2026, and covers 2,303,416 unique email addresses. Verified data categories include dates of birth, email addresses, gender information, marital status information, full names, phone numbers, and physical addresses. The record is considered a broad personal data set that could affect donor, supporter, student, and alumni groups.\u003C\u002Fp>\u003Cp>In this incident, the password or payment card field is not among the verified data classes; the severity of the risk comes from the combination of identity, contact, address, and institutional relationship data. Since Moody Bible Institute has a religious education context, a person's relationship as a donor, student, alumnus, or supporter may be additionally sensitive in terms of privacy. Therefore, the record is assessed not only as a contact data leak but as a security incident that could reveal a person's connection to their religious and educational environment.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data verified in this record are birth dates, email addresses, gender information, marital status information, full name, phone numbers, and physical addresses. Email addresses and phone numbers can be used to send fake institution notifications, donation requests, account verification, or support messages. When full name, physical address, and birth date are found together, the risk of misuse increases in identity impersonation, targeted fraud, and account recovery processes.\u003C\u002Fp>\u003Cp>Gender and marital status information provides additional context about the user profile. While these fields alone do not enable account takeover, they can help make social engineering messages appear personalized. Information about institutional affiliation is also important; individuals within the circles of donors, supporters, students, or alumni can be targeted with fake donation requests, educational account update messages, or phone calls appearing to come from the institution. Since the password is not verified, the primary risk is not the account password but the combination of identity and contact information.\u003C\u002Fp>\u003Cul>\u003Cli>Email and phone information directly increase the risk of contact.\u003C\u002Fli>\u003Cli>Name, address, and date of birth can be used in identity theft scenarios.\u003C\u002Fli>\u003Cli>Gender and marital status information can make targeted messages more convincing.\u003C\u002Fli>\u003Cli>Institutional affiliation may pose an additional privacy risk due to religious and educational environment.\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The Moody Bible Institute record is limited to the incident dated June 15, 2026, 2,303,416 affected email addresses, and seven verified data classes. The record matches the moody.edu domain and the Moody Bible Institute header. The incident is associated with the data theft and extortion process observed in June 2026; the subsequently published data set contained personal data belonging to different institutional relationship groups such as donors, supporters, students, and alumni.\u003C\u002Fp>\u003Cp>In this record, password, bank account, payment card, health data, official ID number, academic grade, religious belief field, or private message were not added as verified data classes. The context of a religious institution is considered in sensitivity assessment, but data fields are kept limited to the list verified in sources. This distinction both makes the risk visible and prevents unsupported fields from being presented to the user as definite information. Duplicate checking was carried out based on name, field name, date, number, and data classes.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The primary risk group consists of individuals who have a relationship as donors, supporters, students, alumni, applicants, employees, or service partners with Moody Bible Institute. Due to their email and phone information, these individuals may be targeted with fake institutional announcements, donation campaigns, account verification messages, or personal information update requests. Since physical address and date of birth are included in the same record, more convincing messages can be created based on family, address, and identity context.\u003C\u002Fp>\u003Cp>People who have had a long-term relationship with the institution, who have not changed their contact information for years, whose address remains fixed, or who use the same email address for religious education, donations, work, and personal accounts are at higher risk. From an institutional perspective, donor relations, alumni communications, student services, and financial teams can also be targeted. Attackers can use real personal information to impersonate internal correspondence, create fake payment requests, or prepare support messages that appear trustworthy.\u003C\u002Fp>\u003Cul>\u003Cli>Donor, supporter, student, and alumni groups\u003C\u002Fli>\u003Cli>People who use the same email or phone information for a long time\u003C\u002Fli>\u003Cli>Users whose address and date of birth information matches with old records\u003C\u002Fli>\u003Cli>Internal donor, alumni, and student communication teams\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>In this record, the user who sees the result must first determine through which email, phone, and address they established their relationship with Moody Bible Institute. Unexpected requests for donations, information updates, account verification, or document sharing on behalf of the institution must be verified through an independent channel. Even if the password field is not verified, the email account is critical and should use a unique password and multi-factor authentication. In suspicious phone calls, birth date, address, or one-time codes should not be shared.\u003C\u002Fp>\u003Cp>Since there is address and date of birth information, credit freezing, fraud alerts, mail forwarding changes, and identity monitoring options can be considered. Donations or educational links received due to institutional affiliation should be checked from the known official domain, not directly from the message content. If the same contact information has been used on other donation platforms, educational portals, or community systems, the notification and session histories of these accounts should also be examined.\u003C\u002Fp>\u003Cul>\u003Cli>Use a strong password and multi-factor authentication on your email account.\u003C\u002Fli>\u003Cli>Verify donation and information confirmation requests received on behalf of the institution through a separate channel.\u003C\u002Fli>\u003Cli>Reject requests for code, address, and date of birth verification coming via phone.\u003C\u002Fli>\u003Cli>Consider the options of freezing the credit or a fraud warning.\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>At institutions like Moody Bible Institute, the risk to personal data persists for a long time because names, addresses, phone numbers, birth dates, and institutional affiliation may not change over the years. Users should keep separate email addresses for religious institutions, educational platforms, donation systems, and alumni networks, close unnecessary old accounts, and regularly review their communication preferences. Email masking, a separate phone number, and strong account notifications reduce risk in the long term.\u003C\u002Fp>\u003Cp>This incident demonstrates the importance of segmentation, access control, multi-factor authentication, third-party audits, and transparent post-incident communication in protecting donor and student data for institutions. Employees should be trained against fake messages prepared with real person's data, and a secondary approval process should be used for donation or account change requests. Personal data inventory, backup, record retention period, and leak monitoring processes should be tested regularly.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>A user who sees a Moody Bible Institute result on LeakData.io should determine which institutional affiliation the matching email address was used with. The result may not mean that the user is currently an active student or donor; historical affiliation data may also be included in this record. Still, since the email, phone, address, and date of birth fields are found together, the result should be taken seriously, and caution should be exercised, especially against fake donation and institutional communication messages.\u003C\u002Fp>\u003Cp>This record is kept in a verified status and is limited to seven data classes. Since the password or payment card is not verified, the focus should be on the identity, communication, and institutional relationship risk rather than unnecessary fear. When the user strengthens account security and verifies suspicious communications through an independent channel, it can reduce the impact of this breach on daily account and identity security.\u003C\u002Fp>","Moody Bible Institute Data Breach (2.3 Million Reported Records)","Moody Bible Institute Data Breach. 2.3 Million reported records are reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope…","\u002Fuploads\u002Flogo\u002Fmoody_edu.png",false,{"name":7,"sector":44,"country":45,"website":10,"websiteArchiveUrl":46,"websiteStatus":46,"websiteCheckedAt":13},"Education \u002F Religious institution","United States",""]