---
title: "Moody Bible Institute data incident"
description: "Evidence-backed account of Moody Bible Institute data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/moody-bible-institute-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/moody-bible-institute-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/moody-bible-institute-data-incident-2026/stix.json"
---

# Moody Bible Institute data incident

Moody Bible Institute disclosed an investigation after cybercriminals claimed access to certain internal systems. HIBP lists contact and demographic data associated with the Moody Bible Institute incident.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[Moody Bible Institute](https://www.moody.edu/) disclosed an investigation after cybercriminals claimed access to certain internal systems. [1](#source-1) [2](#source-2)

## Impact

HIBP lists contact and demographic data associated with the Moody Bible Institute incident. [1](#source-1) [2](#source-2)

Documented data types include:

- Demographic information — Marital statuses listed for records in the HIBP incident corpus. [1](#source-1)
- Dates of birth — Dates of birth listed for records in the HIBP incident corpus. [1](#source-1)
- Contact information — Email addresses, phone numbers, and physical addresses listed for records in the HIBP incident corpus. [1](#source-1)
- Gender information — Gender information listed for records in the HIBP incident corpus. [1](#source-1)
- Names — Names listed for records in the HIBP incident corpus. [1](#source-1)

A cited record reports 2,303,416 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a Moody-confirmed affected-person count; as of 2026-07-03). [1](#source-1)

HIBP reported that the associated data was later published publicly. [1](#source-1)

Moody advised vigilance, account-statement review, reporting unauthorized transactions, credit freezes and fraud alerts, and strong unique passwords; it said it would contact specific affected people if warranted. [2](#source-2)

## Timeline

### June 15, 2026 — Documented event

Day-level incident date in HIBP; Moody's June 22 notice says the incidents occurred the prior week without identifying an exact date. [1](#source-1) [2](#source-2)

### June 22, 2026 — Public disclosure

Publication date of Moody's data-incident investigation notice. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

As of June 22, Moody said the investigation remained ongoing and that it was still working to understand the nature of the data compromised and the incident's full scope. The Information Technologies Services team implemented security protocols to address the vulnerability and engaged internal and external cybersecurity experts. Moody Bible Institute said cybercriminals claimed they had hacked into certain internal systems. Moody notified appropriate law-enforcement authorities and said it was cooperating with them. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/moody-bible-institute-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Moody Bible Institute breach record

advisory · Have I Been Pwned · Jul 3, 2026

<https://haveibeenpwned.com/api/v3/breach/MoodyBibleInstitute>

<a id="source-2"></a>

### Moody Bible Institute Data Incident Investigation

official · Moody Bible Institute · Jun 22, 2026

<https://www.moodybible.org/news/2026/data-investigation/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Record Count · 100% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: 2,303,416 record
2. **Resulted In · 90% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: HIBP reported that the associated data was later published publicly.
3. **Exposed Data Category · 100% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: Demographic information
4. **Resulted In · 90% confidence · current**  
   June 2026 Moody Bible Institute data incident: Moody Bible Institute HIBP corpus exposure
5. **Resulted In · 100% confidence · current**  
   June 2026 Moody Bible Institute data incident: As of June 22, Moody said the investigation remained ongoing and that it was still working to understand the nature of the data compromised and the incident's full scope.
6. **Resulted In · 100% confidence · current**  
   June 2026 Moody Bible Institute data incident: The Information Technologies Services team implemented security protocols to address the vulnerability and engaged internal and external cybersecurity experts.
7. **Resulted In · 100% confidence · current**  
   June 2026 Moody Bible Institute data incident: Moody Bible Institute said cybercriminals claimed they had hacked into certain internal systems.
8. **Disclosed At · 100% confidence · current**  
   Moody Bible Institute June 2026 data-incident disclosure: 2026-06-22
9. **Exposed Data Category · 100% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: Dates of birth
10. **Resulted In · 100% confidence · current**  
   June 2026 Moody Bible Institute data incident: Moody notified appropriate law-enforcement authorities and said it was cooperating with them.
11. **Occurred At · 90% confidence · current**  
   June 2026 Moody Bible Institute data incident: 2026-06-15
12. **Exposed Data Category · 100% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: Contact information
13. **Exposed Data Category · 100% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: Gender information
14. **Affected Organization · 100% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: Moody Bible Institute
15. **Resulted In · 100% confidence · current**  
   Moody Bible Institute June 2026 data-incident disclosure: Moody advised vigilance, account-statement review, reporting unauthorized transactions, credit freezes and fraud alerts, and strong unique passwords; it said it would contact specific affected people if warranted.
16. **Exposed Data Category · 100% confidence · current**  
   Moody Bible Institute HIBP corpus exposure: Names
17. **Affected Organization · 100% confidence · current**  
   June 2026 Moody Bible Institute data incident: Moody Bible Institute
18. **Resulted In · 100% confidence · current**  
   June 2026 Moody Bible Institute data incident: Moody Bible Institute June 2026 data-incident disclosure

</details>
