Moody Bible Institute data incident

Moody Bible Institute disclosed an investigation after cybercriminals claimed access to certain internal systems. HIBP lists contact and demographic data associated with the Moody Bible Institute incident.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Moody Bible Institute disclosed an investigation after cybercriminals claimed access to certain internal systems. [1][2]

Impact

HIBP lists contact and demographic data associated with the Moody Bible Institute incident. [1][2]

Documented data types include:

  • Demographic information — Marital statuses listed for records in the HIBP incident corpus. [1]
  • Dates of birth — Dates of birth listed for records in the HIBP incident corpus. [1]
  • Contact information — Email addresses, phone numbers, and physical addresses listed for records in the HIBP incident corpus. [1]
  • Gender information — Gender information listed for records in the HIBP incident corpus. [1]
  • Names — Names listed for records in the HIBP incident corpus. [1]

A cited record reports 2,303,416 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a Moody-confirmed affected-person count; as of 2026-07-03). [1]

HIBP reported that the associated data was later published publicly. [1]

Moody advised vigilance, account-statement review, reporting unauthorized transactions, credit freezes and fraud alerts, and strong unique passwords; it said it would contact specific affected people if warranted. [2]

Timeline

  1. Documented event

    Day-level incident date in HIBP; Moody’s June 22 notice says the incidents occurred the prior week without identifying an exact date.

    [1][2]
  2. Public disclosure

    Publication date of Moody’s data-incident investigation notice.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

As of June 22, Moody said the investigation remained ongoing and that it was still working to understand the nature of the data compromised and the incident’s full scope. The Information Technologies Services team implemented security protocols to address the vulnerability and engaged internal and external cybersecurity experts. Moody Bible Institute said cybercriminals claimed they had hacked into certain internal systems. Moody notified appropriate law-enforcement authorities and said it was cooperating with them. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]