New Apostolic Church USA Data Breach Notice (Vermont Attorney General): What Was Exposed & What To Do
New Apostolic Church USA has disclosed a data breach involving the Social Security Numbers of six individuals, as reported to the Vermont Attorney General on June 26, 2026. Individuals are advised to verify whether their information was affected and to take appropriate protective steps.
Faith-based and nonprofit organizations continue to appear in regulatory breach notices alongside larger commercial targets, reflecting a threat landscape in which attackers seek personal data wherever it is stored with limited security resources. Small-scale incidents still matter: even a handful of exposed records can enable identity fraud when the data includes identifiers such as Social Security numbers.
New Apostolic Church USA notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on June 26, 2026. The notice indicates that Social Security numbers were among the information exposed and that six people were affected. Public detail beyond that filing is limited, but the disclosure is consequential for anyone whose identifiers may have been involved and for an organization that holds sensitive personal information in the course of religious and administrative work.
Inside the incident
According to the Vermont Attorney General filing reported on June 26, 2026, New Apostolic Church USA provided notice of a data breach affecting Vermont residents. The filing lists six people as affected and names Social Security numbers among the information exposed. The public record available from that notice does not describe when the incident was discovered, how long unauthorized access may have lasted, what systems were involved, or the technical method used. Scale beyond the stated figure of six affected individuals, any ransom or extortion element, and whether other data types were involved are not detailed in the disclosed summary.
What is established is procedural: the organization submitted a breach notice to the Vermont Attorney General, the notice referenced Social Security numbers, and the affected count reported in connection with that filing is six. No threat actor is named in the facts provided, and no independent forensic narrative has been supplied in the material summarized here. Readers should treat unstated elements—root cause, attack path, and full data inventory—as undisclosed rather than assumed.
How a breach like this happens
Incidents that lead to notices naming Social Security numbers often follow familiar patterns, though none of these patterns is confirmed for this specific case. Organizations may store member, donor, employee, or volunteer records in email systems, shared drives, membership databases, or third-party administrative tools. Attackers commonly gain initial access through phishing, stolen or reused passwords, unpatched remote access services, or compromised vendor accounts. Once inside, they may copy files, export database tables, or exfiltrate backups that contain government identifiers collected for tax, employment, background-check, or benefits purposes.
In other cases, a misconfigured cloud share, an unsecured backup, or malware on a workstation used for administrative work can expose the same categories of data without a dramatic “break-in.” Ransomware groups sometimes steal data before encryption and later claim to publish it; other intrusions are quieter and discovered only through unusual account activity or law-enforcement notice. Because no method is attributed in the New Apostolic Church USA filing summary, these points are general background only. The common thread is that once Social Security numbers leave authorized control, they retain value for fraud long after the technical incident ends.
About New Apostolic Church USA
New Apostolic Church USA is the United States expression of a Christian denomination that maintains congregations, pastoral care, and related administrative functions. Like other religious bodies, such an organization typically holds information needed to serve members and run operations: contact details, household or membership records, donation and accounting data, and, where people are employed or engaged in formal roles, employment and tax-related identifiers. Social Security numbers may appear in payroll, contractor, volunteer screening, or benefits contexts even when the core mission is spiritual rather than commercial.
A breach affecting a church organization is consequential because trust and confidentiality are central to pastoral relationships, and because the people whose data is held often did not choose a commercial “customer” relationship—they joined a faith community. Regulatory notices to state attorneys general exist precisely so that residents can learn when their personal information may have been exposed, regardless of the organization’s size or sector. The Vermont filing places this incident in that public accountability framework.
What was likely exposed
The filing summary names Social Security numbers among the information exposed and reports six people affected. It does not publish a full inventory of every field in every record, nor does it confirm whether names, addresses, dates of birth, financial account numbers, or other elements were included for those individuals. Exact contents beyond the named data type remain limited to what the notice states.
Organizations of this kind commonly maintain, in ordinary operations, names and contact information, membership or household associations, donation histories, and employment or volunteer-related documents that can include government identifiers. That general pattern does not establish what was taken in this incident. Only the disclosed element—Social Security numbers, for a reported six people in the Vermont notice context—should be treated as stated. Anything further is unconfirmed.
Why it matters
Social Security numbers are durable identifiers. In the wrong hands they can support tax refund fraud, new-account identity theft, synthetic identity construction, and attempts to pass knowledge-based authentication at banks, insurers, or government agencies. Even a small number of affected people face outsized personal risk because the harm is individual: monitoring credit, disputing fraudulent accounts, and correcting government records can take months.
For the organization, a breach notice can affect member confidence, trigger notification and support costs, and invite scrutiny of how sensitive identifiers are collected, stored, and retained. For Vermont residents named in or covered by such a notice, the practical issue is whether their SSN and related identity data could be misused. Calm, prompt personal vigilance matters more than speculation about attackers or internal blame, neither of which is established as fact in the public summary provided.
What to do if you're exposed
If you believe you may be one of the people covered by the New Apostolic Church USA notice, treat Social Security number exposure seriously. Consider placing a free fraud alert or credit freeze with the major credit bureaus, reviewing credit reports and IRS online account activity for unfamiliar filings, and watching bank and insurance statements for new accounts or claims you did not open. Keep any official notice letter; it can help when dealing with creditors or agencies. Change passwords on important accounts, especially if you reused credentials tied to church-related email, and enable multi-factor authentication where available.
If you were not contacted but worry your information appears in breach data more broadly, you can run a free exposure scan of your email address to check whether it has surfaced in known breach datasets, then tighten security on any accounts that reuse that address or password. When in doubt, rely on official notices from the organization and guidance from the Vermont Attorney General or Federal Trade Commission rather than unverified third-party claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Petco Animal Supplies Stores, Inc. Data Breach Notice (Vermont Attorney General)Marion Military Institute Data Breach Notice (Vermont Attorney General)Heywood Healthcare Inc. Data Breach Notice (Vermont Attorney General)HILT-Trust 2020-A Data Breach Notice (Vermont Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.