New Covenant Believers’ Church suffered a ransomware attack claimed by the Wallstreet threat actor group, which may have exposed personal and financial information belonging to congregants, staff, or donors. The exact number of affected individuals hasn’t been publicly disclosed. Anyone connected to the church should monitor their credit reports and watch for phishing attempts referencing the ministry immediately.
| Company | New Covenant Believers’ Church |
|---|---|
| Industry | Non-profit |
| Data Types Exposed | Full Names, Contact Information, Financial Information, Social Security Numbers, Dates of Birth, Membership Records |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Vermont Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the New Covenant Believers’ Church Data Breach?
New Covenant Believers’ Church has confirmed that it experienced a ransomware attack affecting its computer network. The organization, a faith-based ministry, discovered that a threat actor group known as Wallstreet had targeted its systems. As a result, sensitive files stored on the church’s network may have been accessed or copied without authorization.
Details about the exact timeline remain limited. The breach discovery date has not been publicly disclosed. However, ransomware groups like Wallstreet typically gain access through phishing emails, stolen credentials, or exploited software weaknesses before locking systems and threatening to leak stolen files.
Once the church identified the intrusion, it began an internal review of the incident. In addition, the organization worked to determine which systems were affected and what data the attackers may have taken. This investigation likely involved forensic specialists who examine network logs to trace how the attackers entered and what they accessed.
Because ransomware attacks often involve both encryption and data theft, the church needed to assess whether personal information was copied before any files were locked. This step is critical for determining who must be notified. As a result, the notification process may still be ongoing for some affected individuals.
Who was affected?
New Covenant Believers’ Church serves a community of congregants, staff, and possibly volunteers who interact with the ministry regularly. Because churches often store data belonging to both employees and members, this breach could affect a wide range of people connected to the organization.
The exact number of affected individuals has not been publicly disclosed. This means the scope of the breach, whether it touched dozens or thousands of records, is currently unknown to the public. Because the church operates as a ministry, it’s possible that donor records, member contact information, or payroll data for staff were involved.
Given the nature of church operations, minors could also be part of the affected population. Many congregations maintain records for youth programs, Sunday school enrollment, or family ministries. Therefore, parents connected to the organization should remain alert for notification letters regarding their children as well as themselves.
What Information Was Potentially Exposed?
While the church has not released a complete inventory of compromised data, ransomware attacks on organizations like this one typically put several categories of personal information at risk. Because churches manage both membership records and administrative data, the exposure could span several types of sensitive details.
- Full names
- Contact information such as addresses, phone numbers, and email addresses
- Financial information related to donations or payroll
- Social Security numbers for employees or volunteers
- Dates of birth
- Membership or congregational records
If Social Security numbers or financial details were part of the stolen data, affected individuals could face a heightened risk of identity theft. Criminals often use this type of information to open new credit accounts, file fraudulent tax returns, or apply for loans under someone else’s name.
In addition, exposed contact information can fuel phishing campaigns. Scammers frequently use stolen names and email addresses to craft convincing messages that appear to come from a trusted source, like a church. As a result, affected individuals should treat unexpected messages referencing the ministry with caution.
What is the company doing?
In response to the attack, New Covenant Believers’ Church has taken steps to investigate the scope of the incident and secure its systems. This likely included isolating affected servers and reviewing network security to prevent further unauthorized access.
The church has also worked to meet its legal notification obligations. Specifically, New Covenant Believers’ Church filed a formal breach notification with the Vermont Attorney General. This filing helps ensure that regulators and affected residents receive proper disclosure about the incident.
Going forward, the organization may continue to strengthen its cybersecurity practices. This can include multi-factor authentication, employee training on phishing awareness, and ongoing monitoring for suspicious network activity. Because ransomware groups often target under-resourced nonprofits, additional safeguards are especially important for organizations like churches.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should request a free copy of their credit report from each of the three major credit bureaus. Reviewing these reports carefully can help you spot unfamiliar accounts or inquiries early.
Because identity thieves often act quickly after a breach, checking your credit report regularly over the next year is wise. If you notice anything unusual, report it immediately to the credit bureau and consider placing a fraud alert.
Consider a Fraud Alert or Credit Freeze
If Social Security numbers or financial account details were exposed, placing a fraud alert or credit freeze can add an important layer of protection. A fraud alert requires creditors to verify your identity before opening new accounts in your name.
A credit freeze goes a step further by restricting access to your credit file entirely. As a result, most identity thieves won’t be able to open new lines of credit even if they have your personal information. You can freeze your credit for free with each bureau.
Watch for Phishing and Suspicious Communications
Because attackers often use stolen contact details to impersonate trusted organizations, affected individuals should be cautious of unexpected emails, texts, or calls referencing the church. Never click links or provide personal information unless you can verify the sender’s identity.
If you receive a suspicious message claiming to be from New Covenant Believers’ Church, contact the organization directly using a verified phone number. This simple step can help you avoid falling victim to a follow-up scam tied to this breach.
Keep Records and Document Any Suspicious Activity
If you notice unusual account activity, unfamiliar charges, or signs of identity theft, document everything carefully. Keep copies of statements, letters, and any communication related to the incident.
This documentation can prove valuable if you need to dispute fraudulent charges or file a report with law enforcement. In addition, thorough records may support a future legal claim if you decide to consult with an attorney about your options.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
View the public data breach notification listing from Vermont Attorney General
