Archdiocese of Indianapolis Data Breach Exposes Social Security Numbers and Financial Data

Non-profit data breach illustration
Breach Discovery: December 2024Breach Notification: March 2025

What Happened in the Archdiocese of Indianapolis Data Breach?

The Archdiocese of Indianapolis has confirmed a data security incident that exposed sensitive personal records tied to its parishes, schools, and ministries. The organization oversees dozens of Catholic institutions across central Indiana, and its systems hold data on employees, students, parents, and donors. This breadth of stored information is what makes the incident significant for so many different groups of people.

According to filings with state regulators, the unauthorized access occurred in December 2024. The Archdiocese did not publicly detail the exact method attackers used to get into its network. However, it did confirm the intrusion and began the process of notifying affected individuals and government offices afterward.

Notably, this case has continued to develop well past its original disclosure. In July 2026, the Archdiocese filed an additional notification with the Vermont Attorney General’s Office, confirming that at least one Vermont resident’s data was also involved. This means the organization is still identifying affected individuals and jurisdictions more than a year after its first regulatory filing.

Because the Archdiocese first reported the incident to Indiana’s Attorney General in March 2025, roughly 15 months passed before the Vermont filing surfaced. This kind of staggered disclosure is not unusual in large-scale breach investigations. As a result, individuals should not assume the matter is closed just because they haven’t yet received a letter.

Who was affected?

The Archdiocese of Indianapolis has identified employees, students, parents or guardians, and donors as potentially affected. Because the organization runs parishes, schools, and social ministries, the population touched by this breach spans a wide range of ages and relationships to the institution. For example, payroll records for staff sit alongside enrollment files for children and financial details tied to donors.

The Archdiocese has not disclosed the total number of individuals affected nationwide. What is known is that at least one Vermont resident was involved, in addition to individuals notified in Indiana. Given the scope of institutions under the Archdiocese’s umbrella, the true reach of this incident may extend to thousands of families, employees, and supporters.

Because student and parent or guardian information was involved, minors may also be affected. This raises particular concern, since children’s identities are often exploited for years before any fraud is noticed. Therefore, families with children enrolled in Archdiocese-affiliated schools should pay close attention to any notification they receive.

What Information Was Potentially Exposed?

Regulatory filings indicate that several categories of sensitive personal data were involved in this incident. Not everyone affected necessarily had every category exposed, and the Archdiocese has said individual notification letters specify which data types applied to each person.

  • Full names
  • Social Security numbers
  • Dates of birth
  • Home addresses
  • Contact information
  • Financial account information
  • Student ID numbers
  • Parent or guardian information

This combination of data is especially valuable to identity thieves. Social Security numbers paired with dates of birth and financial account details can allow criminals to open new credit lines, file fraudulent tax returns, or apply for loans using someone else’s identity. In addition, having a home address and contact information makes it easier for scammers to craft convincing phishing attempts.

The presence of student and parent or guardian information raises the stakes further. Children rarely check their credit, so fraud involving a minor’s Social Security number can go undetected for years. Because of this, families should treat any notification involving a child’s data with particular urgency.

What is the company doing?

Once the Archdiocese of Indianapolis identified the security incident, it launched an investigation into the scope of the exposure. It then reported the matter to the Indiana Attorney General’s Office in March 2025, fulfilling its obligation under state breach notification law. This filing outlined the categories of data involved and the timeline of the incident.

Since that initial filing, the Archdiocese has continued to identify additional affected individuals and jurisdictions. The July 2026 notification to Vermont regulators shows that the investigation remained active well beyond the first public disclosure. This suggests the organization is still working through its records to determine the full extent of who was impacted.

The Archdiocese has not publicly detailed specific remediation steps, such as system upgrades or new security protocols. However, organizations that experience this type of incident typically strengthen access controls and monitoring following an intrusion. Affected individuals should watch any notification letter closely for details about credit monitoring or other protective services that may be offered.

What Should Affected Individuals Do?

Place a Fraud Alert or Credit Freeze

Because Social Security numbers and financial account information were exposed, placing a fraud alert or credit freeze with the three major credit bureaus is one of the most effective protective steps available. A freeze restricts access to your credit file, making it much harder for criminals to open new accounts in your name.

This step is especially important for anyone whose data included both a Social Security number and date of birth, since that combination is often enough to pass identity verification checks. Setting up a freeze is free and can be lifted temporarily whenever you need to apply for credit yourself.

Monitor Credit Reports and Financial Statements

Regularly reviewing your credit reports and bank statements can help you catch unauthorized activity early. You are entitled to a free credit report from each of the three bureaus every year, and checking them on a staggered schedule lets you monitor your credit throughout the year.

In addition to credit reports, review bank and credit card statements for small or unfamiliar charges. Fraudsters sometimes test stolen financial information with tiny transactions before attempting larger fraud. Catching these early can prevent more significant losses later.

Check for Signs of Child Identity Theft

If your child’s information was included in the exposed student or parent or guardian data, consider checking whether a credit file already exists in their name. Since children typically have no credit history, the existence of any credit file is a red flag for identity theft.

You can request a manual credit check for a minor through the credit bureaus, which generally require proof of identity and guardianship. Because child identity theft often goes unnoticed for years, taking this step proactively is worthwhile even if nothing seems wrong right now.

Stay Alert for Phishing Attempts

Following any data breach, scammers often send emails, texts, or phone calls that reference the incident to appear legitimate. Be cautious of any message claiming to be from the Archdiocese, a parish, or a school that asks for personal information or payment.

Instead of clicking links in unsolicited messages, contact the organization directly using a verified phone number or website. This simple habit can prevent you from unknowingly handing over additional information to criminals posing as trusted institutions.

Keep Records and Consider Legal Options

If you receive a notification letter, keep it in a safe place along with any related correspondence. This documentation may be necessary if you decide to pursue a legal claim related to the breach.

Organizations that collect sensitive personal and financial data are expected to protect it with reasonable safeguards. If those safeguards failed here, affected individuals may have legal options worth exploring. Speaking with a data breach attorney for a free case evaluation can help clarify what compensation, if any, might be available to you.



Related Data Breaches

See the latest data breaches we're tracking →