New Apostolic Church USA Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do
New Apostolic Church USA disclosed a data breach affecting 12 individuals on June 27, 2026, exposing Social Security numbers, financial account numbers, and driver’s license numbers. Anyone who may have been involved should review the notice filed with the Massachusetts Attorney General and take steps to protect their information.
A small number of people connected to New Apostolic Church USA may have had highly sensitive personal information exposed in a data breach the organization reported in mid-2026. Public notice filed with Massachusetts authorities states that Social Security numbers, financial account numbers, and driver’s license numbers were among the data involved, which raises concrete risks of identity theft and financial fraud for anyone whose records were included.
The filing indicates twelve people were affected. Even at that limited scale, the categories of information named are among the most useful to criminals who open accounts, file false claims, or impersonate victims. What follows summarizes only what the disclosure states and places it in plain context for those who may need to act.
Inside the incident
New Apostolic Church USA notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on June 27, 2026. The notice, associated with the Massachusetts Attorney General’s data-breach reporting channel, lists Social Security numbers, financial account numbers, and driver’s license numbers among the information exposed. The organization reported that twelve people were affected.
Public detail beyond that notice is limited. The available record does not describe how the incident was discovered, whether systems were accessed by an unauthorized party, whether ransomware or another method was involved, the precise window of exposure, or which systems or files were implicated. No threat actor is named in the disclosure. Readers should treat any further claims that appear outside official notices as unverified unless the organization or a regulator confirms them.
How a breach like this happens
Incidents that result in notices naming government identifiers and financial account data often follow familiar patterns, though none of these patterns is confirmed for this specific case. Attackers commonly gain an initial foothold through stolen or guessed credentials, phishing messages that trick staff into revealing passwords or running malware, unpatched software, or misconfigured remote access. Once inside a network or cloud account, they may search for databases, membership systems, payroll or donation records, or document stores that contain concentrated personal information.
In other cases, a vendor that processes payments, background checks, or membership administration is compromised, and the customer organization later learns that its data was among what was taken. Sometimes the exposure is accidental—an unsecured file share, a misdirected export, or a device lost without encryption—rather than a deliberate intrusion. Organizations typically investigate, determine whose records were involved, and then issue legally required notices when certain data types are confirmed or reasonably believed to have been accessed. The Massachusetts filing reflects that notification step; it does not by itself establish the technical root cause.
Who is New Apostolic Church USA?
New Apostolic Church USA is the United States expression of a Christian denomination that maintains congregations, pastoral care, and related administrative functions. Like many faith-based and nonprofit organizations, such bodies commonly hold membership rolls, contact details, contribution or donation records, volunteer or employee information, and sometimes identification documents needed for employment, background screening, travel, or financial administration.
A breach affecting a church organization is consequential because the data it holds is often trusted and relatively stable over time—names tied to long-term membership, family relationships, and giving history. Even when the number of people formally notified is small, the sensitivity of tax identifiers and financial account numbers means the practical harm can be outsized for those individuals. Religious and community organizations also rely on trust; any confirmed exposure of personal data can affect how members and donors weigh future sharing of information.
What data was at risk
According to the notice reported on June 27, 2026, the information exposed included Social Security numbers, financial account numbers, and driver’s license numbers. The filing states that twelve people were affected. The public summary does not itemize additional fields, does not say whether full account credentials or medical data were involved, and does not describe the format or completeness of the records.
Organizations of this kind often also maintain names, addresses, phone numbers, email addresses, dates of birth, and contribution histories in ordinary operations. Those categories are not confirmed as exposed in this incident. Only the data types named in the Massachusetts notice should be treated as established for the people who received notification.
Why it matters
Social Security numbers and driver’s license numbers are durable identifiers. Once they circulate, they can be reused for years to attempt new credit accounts, government-benefit fraud, tax-refund fraud, or synthetic identities. Financial account numbers can enable unauthorized withdrawals, fraudulent transfers, or social-engineering attacks against banks if combined with other personal details. Even a notice covering only twelve people does not reduce the severity for each person whose identifiers were included.
For the organization, the incident carries operational and trust costs: investigation, notification, possible credit-monitoring offers, and the need to harden systems and vendor arrangements. For affected individuals, the main concerns are monitoring for new-account fraud, watching existing bank and credit activity, and correcting any false information that appears on credit reports or with government agencies. Calm, prompt steps matter more than alarm.
If your data was in this breach
If you received a notice from New Apostolic Church USA or believe you may be one of the twelve people referenced in the Massachusetts filing, practical first steps include the following:
- Read the official notice carefully and keep a copy; note any reference numbers, dates, and offered services such as credit monitoring.
- Place a free fraud alert or consider a credit freeze with the major credit bureaus so new credit is harder to open in your name.
- Monitor bank, credit-card, and investment accounts for unfamiliar transactions, and report anything suspicious to the institution immediately.
- Review your Social Security statement and tax filings for signs of misuse, and be cautious of unsolicited calls or messages that reference the breach.
- Change passwords on important accounts, enable multi-factor authentication where available, and avoid reusing passwords across sites.
- If driver’s license data was involved, check with your state motor-vehicle agency about steps to flag or replace the license if recommended.
You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which can help you prioritize password changes and monitoring. Official updates should come from the organization or from state consumer-protection channels; treat third-party leak claims with caution unless they are corroborated by those sources.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Spectrum Laboratory Products, Inc. Data Breach Notice (Massachusetts Attorney General)Murfreesboro Medical Clinic Data Breach Notice (Massachusetts Attorney General)Healthfirst Bluegrass, Inc. Data Breach Notice (Massachusetts Attorney General)Bell American Group LLC Data Breach Notice (Massachusetts Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.