← Knowledge Center
Breach

Moody Bible Institute breach exposes 2.3M records in ShinyHunters extortion

Moody Bible Institute was hit by a ShinyHunters extortion campaign in June 2026, with the attackers ultimately publishing data after the ‘pay or leak’ demand played out. The exposed dataset covers over 2.3 million unique email addresses along with names, physical addresses, phone numbers, and dates of birth belonging to donors, supporters, students and alumni.

While no passwords or authentication secrets were reported in this dump, the combination of email addresses, dates of birth, and physical details creates a rich foundation for credential-stuffing, targeted phishing, and social engineering against affected individuals and any organizations where they hold accounts.

What to take away: Personal data leaks like this feed downstream identity attacks. Organizations should watch for the newly exposed addresses in credential-stuffing and phishing attempts, and affected users should enable MFA and remain alert to identity-themed lures referencing their real personal details.

Primary source

Have I Been Pwned

Read at haveibeenpwned.com ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.