Moody Bible Institute of Chicago Data Breach Exposes Personal and Financial Information

Education data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

Moody Bible Institute of Chicago disclosed a data breach that may have exposed personal information, potentially including Social Security numbers and financial details, belonging to students, staff, or donors. The exact number of people affected has not been publicly disclosed. Affected individuals should immediately check their credit reports and consider placing a fraud alert or credit freeze to guard against identity theft.

CompanyMoody Bible Institute of Chicago
IndustryEducation
Data Types ExposedFull Names, Social Security Numbers, Financial Account Information, Contact Information
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedCalifornia Attorney General, Washington State Attorney General

What Happened in the Moody Bible Institute of Chicago Data Breach?

Moody Bible Institute of Chicago recently confirmed that it experienced a data security incident involving personal information. The organization disclosed the breach through formal notification filings submitted to state regulators. As a result, affected individuals are now being told that their private data may have been compromised.

According to the notification filed in July 2026, the exact date the breach was first discovered has not been publicly disclosed. However, the institute did confirm that it identified unauthorized activity affecting systems that stored personal information. Because many organizations only learn of these intrusions well after the fact, the timeline between initial compromise and detection often remains unclear.

Once the issue came to light, Moody Bible Institute of Chicago took steps to investigate the scope of the incident. This typically involves bringing in forensic specialists to determine what data was accessed and how the intrusion occurred. At this stage, the institute has not publicly detailed the specific method the attacker used to gain access.

Following the investigation, the institute moved to notify regulators and affected individuals, consistent with its legal obligations. This notification process is often the first public confirmation that a breach has taken place. As more details emerge, additional information about the root cause may become available.

Who was affected?

The population affected by this breach has not been fully detailed in public filings. Given that Moody Bible Institute is an educational and religious institution, those impacted could include current and former students, faculty, staff, or donors. In some cases, breaches at educational institutions also affect family members listed in financial aid or emergency contact records.

The exact number of individuals affected has not been publicly disclosed. Therefore, anyone who has ever interacted with the institute, whether as a student, employee, applicant, or supporter, should consider themselves potentially at risk until more specific guidance is released. Because educational institutions often retain records for many years, individuals affected could include people who had contact with Moody years ago.

It also remains unclear whether the breach involves records limited to Illinois, where the institute is based, or extends to individuals nationwide. Since Moody Bible Institute has students and alumni across the country, the geographic scope of affected individuals could be broad. In addition, because some students enroll as minors or young adults, there is a possibility that younger individuals’ data was involved.

What Information Was Potentially Exposed?

Public filings confirm that personal information was involved in this breach, though the institute has not released an exhaustive list of every data element affected. Based on the nature of similar breaches at educational and nonprofit institutions, the categories of information at risk commonly include the following.

  • Full names
  • Social Security numbers
  • Financial account information
  • Contact information such as addresses or phone numbers
  • Other personal identifiers tied to student, employee, or donor records

When Social Security numbers and financial details are exposed, the risk of identity theft rises significantly. Criminals can use this type of information to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. This kind of fraud can take months to detect and even longer to fully resolve.

Beyond financial fraud, exposed personal information can also be used for phishing schemes that appear highly convincing. For example, scammers may pose as the institute itself, referencing real details from the breach to build trust. As a result, affected individuals should treat any unexpected communication referencing Moody Bible Institute with heightened caution.

What is the company doing?

In response to the breach, Moody Bible Institute of Chicago began an internal review to determine the scope of the incident. This response generally includes securing affected systems and working to prevent further unauthorized access. The institute has also taken steps to formally notify individuals whose information may have been involved.

In addition to notifying impacted individuals, the institute filed formal breach notifications with government regulators. It filed with the California Attorney General and the Washington State Attorney General. These filings are a standard part of the legal notification process and help ensure transparency for affected residents in those states.

Going forward, the institute is likely to continue monitoring its systems for further suspicious activity. Many organizations also use these incidents to strengthen internal security controls and employee training. Although specific protective services offered to affected individuals have not been detailed publicly, similar breaches often include an offer of credit monitoring or identity protection.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone notified about this breach should begin checking their credit reports regularly. This is one of the simplest ways to catch signs of fraud early. You can request free credit reports from all three major credit bureaus through AnnualCreditReport.com.

Because fraudulent accounts can appear months after a breach, it’s important to check reports on an ongoing basis rather than just once. If you notice unfamiliar accounts or inquiries, report them immediately to the credit bureau and consider filing a police report. Early detection often makes resolving fraud much easier.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers and financial information may have been exposed, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further by restricting access to your credit file entirely.

Both options are free to set up and can be requested directly through each credit bureau. While a freeze offers stronger protection, it does require you to lift it temporarily whenever you apply for new credit. Either step can significantly reduce the chances of someone opening fraudulent accounts using your information.

Stay Alert for Phishing Attempts

Because attackers often use stolen personal details to craft convincing scams, it’s important to stay cautious with unexpected emails, calls, or texts. Watch for messages that reference this breach or claim to be from Moody Bible Institute. Legitimate organizations will never ask you to confirm sensitive information through unsolicited communication.

If you receive a suspicious message, avoid clicking any links or downloading attachments. Instead, contact the organization directly using a verified phone number or website. This simple habit can prevent a phishing attempt from turning into a full identity theft incident.

Review Financial and Account Statements

In addition to monitoring credit reports, review your bank and credit card statements closely for unfamiliar charges. Even small, unexplained transactions can be a sign that your financial information has been compromised. Catching these early can prevent larger losses down the line.

If you spot anything suspicious, contact your financial institution right away to dispute the charge and request a new card if needed. Many banks also offer fraud monitoring alerts that notify you of unusual activity in real time. Enabling these alerts adds another layer of protection while the investigation into this breach continues.



More Information

Official data breach notification from California Attorney General

Official data breach notification report (PDF) from Washington State Attorney General

Related Data Breaches

Check other recent data breach notifications →