Moody Bible Institute, a Chicago-based Christian higher education organization, is tied to a June 2026 data leak indexed by leaksear.ch with 2,225,599 records (leaksear.ch metadata, cyberinsider.com). The indexed records include emails, names, physical addresses, phone numbers, dates of birth, and related donor, supporter, student, and alumni information (leaksear.ch metadata).
What happened
CyberInsider reported on June 18, 2026 that Moody Bible Institute appeared on a ShinyHunters extortion site, where the group claimed it had stolen more than 23 GB of data from the institution. At the time, Moody told CyberInsider it was aware of the claim and had engaged cybersecurity experts, while CyberInsider noted the institution had not yet confirmed the breach and that the threat actor's claims remained unverified (cyberinsider.com).
Moody later published a June 22, 2026 data incident statement saying it was among several colleges and universities where cyber criminals claimed they hacked certain internal systems. The institution said its IT team implemented security protocols, engaged internal and external cybersecurity experts, notified law enforcement, and was still working to understand the nature of any compromised data (moodybible.org).
Have I Been Pwned lists the incident as a June 2026 ShinyHunters pay-or-leak extortion campaign and says more than 2.3 million unique email addresses and other personal data were later published publicly. Mozilla Monitor lists the breach date as June 15, 2026 and says the verified breach was added to its database on July 3, 2026 (haveibeenpwned.com, monitor.mozilla.org).
What data was exposed
The leaksear.ch index contains records with names, email addresses, phone numbers, physical addresses, countries, and dates of birth as searchable fields (leaksear.ch metadata). The metadata also indicates stored record context such as state and country codes, created and modified dates, internal IDs, legacy lead identifiers, lead URLs, email opt-out status, and gift-related fields associated with Moody donor, supporter, student, and alumni records (leaksear.ch metadata).
Have I Been Pwned separately lists dates of birth, email addresses, names, phone numbers, physical addresses, genders, and marital statuses as compromised data in the Moody Bible Institute breach (haveibeenpwned.com).
Why this matters
A dataset that combines contact information, addresses, dates of birth, and institutional relationship context can support targeted phishing, social engineering, account recovery abuse, and identity verification fraud. The FBI's IC3 warned in a ShinyHunters advisory that compromised education-sector data can be reused to impersonate school faculty, IT support, financial aid offices, or other trusted contacts in future attacks (ic3.gov). Moody also advised readers to remain vigilant for misuse of personal information, review financial and online account statements, report unauthorized transactions, consider credit freezes and fraud alerts, and use strong unique passwords (moodybible.org). If you had a relationship with Moody Bible Institute, check whether your data appears in this leak using the available search pivots: email, name, phone, address, country, and date of birth.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, country, date of birth, email, name, and phone.
Sources
- Have I Been Pwned: Moody Bible Institute Data Breach
- Mozilla Monitor: Moody Bible Institute Data Breach
- Moody Bible Institute: Data Incident Investigation
- CyberInsider: Moody Bible Institute investigates potential data breach incident
- IC3: ShinyHunters: Cyber Criminal Group Attacks Learning Management System