New Apostolic Church USA Data Breach Notice (Indiana Attorney General): What Was Exposed & What To Do
The New Apostolic Church USA disclosed a data breach on June 26, 2026, that occurred on October 25, 2025 and exposed personal information of 31 individuals. Individuals who may have been affected are urged to review the Indiana Attorney General’s notice and follow any recommended steps to protect their information.
A small number of people connected to New Apostolic Church USA may have had personal information exposed in a cyber incident the church later reported to Indiana authorities. For those individuals, the practical stakes are straightforward: once personal data leaves an organisation’s control, it can be misused for identity fraud, targeted scams, or unwanted contact, even when the total number of people involved is limited.
According to a filing reported to the Indiana Attorney General on June 26, 2026, New Apostolic Church USA notified Indiana residents of a data breach. That filing places the incident itself on October 25, 2025, and states that 31 people were affected. The notice describes the exposed material as personal information; further technical detail in the public record is limited.
What happened
Public reporting on this matter rests on the church’s notice to the Indiana Attorney General. The filing, dated June 26, 2026 in the reported record, states that the underlying incident occurred on October 25, 2025. It identifies 31 people as affected and characterises the exposed data as personal information per the breach notification.
How the incident was discovered, whether systems were encrypted or exfiltrated, what exact systems were involved, and whether a ransom or other demand was made are not set out in the facts available here. No threat actor is named in the disclosure material provided. The gap between the stated incident date and the later attorney-general filing is noted in the record; reasons for that interval are not explained in the summary at hand.
How a breach like this happens
In general terms, incidents that lead to notices like this often begin with routine weak points rather than exotic attacks. Phishing messages can capture staff credentials. Stolen or reused passwords can open remote access. Unpatched software, misconfigured cloud storage, or overly broad permissions can let an intruder move from a single account into files that hold member or contact records. Sometimes a vendor or shared service is the entry point; the organisation that holds the data still bears the duty to notify when personal information is involved.
Once access exists, attackers may copy databases, export spreadsheets, or take email archives. In other cases ransomware operators encrypt systems and also steal data to increase pressure. Not every incident follows that path, and nothing in the public facts for this case attributes a specific method or group. What is common across many such events is a delay between intrusion, internal confirmation of what was taken, legal review, and formal notice to residents and regulators. That pattern helps explain why a notice date can sit months after an incident date without proving either haste or neglect—only that investigation and notification take time.
Who is New Apostolic Church USA?
New Apostolic Church USA is the United States expression of a Christian denomination that organises local congregations, pastoral care, and related administrative work. Churches and similar faith organisations typically maintain records needed to serve members and contacts: names, addresses, phone numbers, email addresses, membership or attendance-related details, and sometimes donation or pastoral notes depending on how ministries are run. They are not banks or hospitals, yet the data they hold is still personal and can be sensitive in context—especially when it ties a person to a faith community, a household, or regular giving.
A breach at a religious organisation matters because trust and pastoral confidentiality sit at the centre of how such groups operate. Even a notice covering a modest headcount can unsettle people who shared information expecting it to stay within church administration. It can also strain volunteer and staff capacity, divert resources to forensics and notification, and raise questions among members about how digital records are protected going forward. The consequential piece is not corporate brand damage in a commercial sense; it is the real exposure of individuals whose relationship with the church involved handing over personal details.
What data was at risk
The facts name the exposed data as personal information, as described in the breach notification. They do not itemise fields such as Social Security numbers, financial account data, dates of birth, or specific document types. Because those finer categories are not disclosed here, they must be treated as unconfirmed.
Organisations of this kind commonly hold identity and contact data used for membership rolls, pastoral outreach, event coordination, and administrative correspondence. Whether any of those typical categories were in fact copied or viewed in this incident is not established beyond the broad label “personal information” in the notice. Readers should not assume a particular data element was included simply because churches sometimes store it.
The real-world impact
For the 31 people referenced in the filing, real-world risk depends on what “personal information” actually contained—something the public summary does not break down. In concrete terms, exposed names and contact details can feed phishing that pretends to come from the church or from a familiar ministry. Broader identity data, if present, can support account takeover attempts or fraudulent applications. Even without dramatic theft, people may face months of heightened vigilance: monitoring accounts, questioning unexpected messages, and dealing with anxiety about who else might have seen their information.
For the organisation, impact includes the duty to notify, possible follow-up with regulators, cost and disruption of investigation and hardening, and the need to communicate clearly with a community that expects care and discretion. A relatively small affected count does not erase those obligations; it simply means the human impact is concentrated on a defined group rather than a mass population. No public fact in the material provided establishes financial loss figures, litigation outcomes, or proof of misuse of the data.
Were you affected?
If you have a past or present connection to New Apostolic Church USA and you received a breach notice, treat that letter or email as the primary source for what applied to you. If you did not receive a notice but remain concerned, you can still take practical steps that help in most personal-data incidents.
- Read any official notice carefully for the date of the incident, what categories of information were involved, and any services the organisation offered (such as credit monitoring).
- Use unique passwords on important accounts and turn on multi-factor authentication where available.
- Watch for phishing that references the church, donations, or “account verification,” and verify requests through known official channels rather than links in unexpected messages.
- Review bank, card, and credit reports for unfamiliar activity if you believe identity data may have been involved.
- Consider running a free exposure scan of your email address to see whether that address has appeared in known breach datasets, which can help you prioritise password changes and monitoring.
Public detail on this incident remains limited to the attorney-general filing summary: an October 25, 2025 incident, notice activity reported June 26, 2026, 31 people affected, and personal information named as exposed. Anything beyond that should be treated as unconfirmed until the organisation or regulators publish more.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
AssuranceAmerica Managing General Agency LLC Data Breach Notice (Indiana Attorney General)Travala Pte Ltd Data Breach Notice (Indiana Attorney General)Graphic Information Systems Inc Data Breach Notice (Indiana Attorney General)North Los Angeles County Regional Center Data Breach Notice (Indiana Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.