LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › The Moody Bible Institute of Chicago Data Breach Notice (Washington Attorney General)

CRITICAL severityConfirmedHow we verify

The Moody Bible Institute of Chicago Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 23, 2026
The Moody Bible Institute of Chicago Data Breach Notice (Washington Attorney General)

Occurred June 12, 2026 · publicly disclosed July 23, 2026. Approximately 8955 people affected.

CRITICAL
Severity
8955
People affected
3
Data types exposed
July 23, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Moody Bible Institute of Chicago disclosed a data breach on July 23, 2026, that occurred on June 12, 2026, exposing the Social Security numbers, driver’s license or Washington ID card numbers, and full dates of birth of 8,955 individuals. If you provided personal information to the Institute, check for any official notice and consider placing a fraud alert or credit freeze.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/financial data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
8955 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Thousands of people may need to treat personal identity details as compromised after The Moody Bible Institute of Chicago reported a data breach affecting 8,955 individuals. A notice filed with the Washington State Attorney General on July 23, 2026, states that Social Security numbers, driver’s license or Washington ID card numbers, and full dates of birth were among the information exposed. For anyone whose records were involved, those data elements are the building blocks of identity theft and fraudulent account opening, so the practical stakes are immediate even when other details of the incident remain limited in the public filing.

The institute placed the incident itself on June 12, 2026. Public detail beyond the headcount, the named data types, and those two dates is limited; the filing does not expand on how systems were reached or how long unauthorized access lasted. What is confirmed is enough to warrant careful monitoring by people who have had a relationship with the organization and who may appear in its records.

What happened

According to the notice reported to the Washington State Attorney General on July 23, 2026, The Moody Bible Institute of Chicago experienced a data breach on June 12, 2026. The filing indicates that 8,955 people were affected. Among the information listed as exposed were Social Security numbers, driver’s license or Washington ID card numbers, and full dates of birth. The public summary does not describe the technical method of intrusion, the systems involved, whether ransomware or other malware was used, or whether data was exfiltrated in bulk versus accessed in place. Those particulars are undisclosed in the material provided.

The notice was directed at least in part to Washington residents, which is why it appears in the state attorney general’s reporting channel. No further breakdown by state, role (student, employee, donor, or other), or time period of the underlying records is given in the disclosed facts.

How a breach like this happens

Incidents that result in notices naming government identifiers and dates of birth often follow familiar patterns, though none of those patterns is confirmed for this specific event. Attackers commonly obtain an initial foothold through stolen or phished credentials, a vulnerable remote-access service, or malicious email that leads to malware on a workstation or server. Once inside, they may move laterally, search file shares and databases for concentrated stores of personal data, and copy what they find. In other cases, a misconfigured cloud repository or an exposed application programming interface simply leaves records reachable without sophisticated intrusion.

Organizations that educate, employ, or serve large numbers of people routinely keep identity documents and tax-related numbers for enrollment, payroll, financial aid, background checks, and compliance. When those repositories are reachable from a compromised account or an unpatched system, the same categories of data named in this notice—Social Security numbers, state ID numbers, and dates of birth—are frequently present together. The absence of a named threat group or detailed forensic narrative in the public filing means the precise path used here remains unconfirmed; the general mechanics above are background only.

Who is The Moody Bible Institute of Chicago?

The Moody Bible Institute of Chicago is a long-established Christian higher-education and ministry organization based in Chicago. Institutions of this kind typically maintain records on students, faculty, staff, applicants, donors, and sometimes alumni or program participants. Those files often include government identifiers required for financial aid, employment tax reporting, housing, and identity verification, along with contact information and dates of birth.

A breach at such an organization is consequential because the data it holds is not limited to a single commercial transaction. Educational and ministry relationships can span years, so a single incident may touch people whose last direct contact with the institute was long ago. The combination of a relatively large affected population—here reported as 8,955—and high-value identity fields raises the likelihood that real-world fraud attempts could follow if the data is misused.

What was likely exposed

The Washington filing explicitly lists Social Security number, driver’s license or Washington ID card number, and full date of birth among the information exposed. Those are the only data types named in the facts provided. Whether additional fields—such as names, addresses, email addresses, phone numbers, student or employee ID numbers, or financial account details—were also involved is not disclosed and therefore unconfirmed.

Organizations in higher education and related nonprofit work commonly store exactly the categories that were named, often alongside contact and demographic data needed for administration. Readers should treat the three named elements as confirmed for the affected population of 8,955 and regard any other category as unknown unless a later official notice expands the list.

Why it matters

Social Security numbers combined with full dates of birth and government-issued ID numbers are sufficient, in many settings, for someone to attempt to open credit accounts, file fraudulent tax returns, obtain medical services, or impersonate a person with government agencies and employers. Harm is not guaranteed in every case, but the risk is concrete and can persist for years because these identifiers are difficult to change.

For the organization, a breach of this type brings notification costs, potential regulatory scrutiny, support obligations to affected individuals, and reputational strain with students, employees, and donors. For individuals, the immediate concerns are credit and identity monitoring, watching for unexpected tax transcripts or benefit claims, and being alert to phishing that references the institute or the breach itself. Because the public notice does not describe encryption status, retention periods, or whether the data was actually downloaded, affected people are left to assume the named fields could be in unauthorized hands.

Were you affected?

If you are a current or former student, employee, applicant, or other affiliate of The Moody Bible Institute of Chicago, watch for an official notification letter or email. Even without a letter, consider placing a fraud alert with the major credit bureaus, reviewing credit reports, and monitoring bank and tax accounts for unfamiliar activity. Change passwords on any accounts that reused credentials tied to institute systems, and be skeptical of unsolicited messages that claim to help with “breach remediation” while asking for more personal data.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which can provide an additional signal alongside any formal notice you receive. Keep records of any official correspondence from the institute and of steps you take to protect your identity.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyThe Moody Bible Institute of Chicago security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See The Moody Bible Institute of Chicago’s full breach history →
RelatedMore incidents at The Moody Bible Institute of Chicago

More recent breaches

Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)August 7, 2026Aesto, LLC (Grant County Public Hospital District #2) Data Breach Notice (Washington Attorney General)August 4, 2026Wilmer Cutler Pickering Hale and Dorr LLP Data Breach Notice (Washington Attorney General)July 15, 2026Kern Psychiatric Health and Wellness Center, Inc Data Breach Notice (California Attorney General)August 21, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the The Moody Bible Institute of Chicago Data Breach Notice (Washington Attorney General) →

Source: Washington State Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram