Moody Bible Institute Breach: 2.3M Records Leaked
ShinyHunters leaked data on 2.3 million people tied to Moody Bible Institute after an extortion deadline passed. What was stolen, and what victims should do.
Data belonging to more than 2.3 million people connected to the Moody Bible Institute (MBI) has been dumped online after the Chicago-based Christian college apparently refused to pay an extortion demand. The leak, tied to the prolific extortion group ShinyHunters, moves the incident out of the quiet disclosure phase and into the far more damaging stage where stolen personal data is publicly searchable — the records have now been added to the Have I Been Pwned database, where anyone can check whether their information is among them.
MBI first disclosed the breach in June 2026. In the weeks since, the story has followed a grimly familiar arc: a negotiation, a deadline, a refusal, and a leak. The result is one of the larger education-sector exposures of the year, and a case study in how a single unpatched weakness can cascade into millions of compromised identities.
What was stolen
According to the exposed data now circulating, the compromised information spans a wide set of personal fields. It includes names, genders, dates of birth, physical and email addresses, phone numbers, and marital statuses. The records are drawn from across the institution’s operations — donor relations, supporters, students, and alumni are all represented in the cache.
ShinyHunters’ own claims go further than MBI’s public statements. The group says it exfiltrated more than 23 gigabytes of data spanning the college’s enrollment, donor relations, payroll, and communications systems. It asserts the haul includes roughly 46 million communication records, about 2.2 million enrollment-lead records, and more than 108,000 biodemographic master files containing names, postal addresses, and dates of birth.
Those figures should be read with caution — extortion groups routinely inflate the scope of a theft to increase pressure on victims and buyers. But the 2.3 million individuals figure reflects the deduplicated count of affected people, and the presence of the data in Have I Been Pwned confirms the leak is real rather than a bluff. Even the confirmed subset is enough to expose a large population to targeted phishing, identity theft, and fraud.
How the leak unfolded
The mechanics here matter, because they explain why the damage escalated. Breaches like this typically move through predictable phases. First, attackers gain access and quietly exfiltrate data. Then the victim is contacted with a ransom demand — pay, or the data goes public. This is the “pay-or-leak” model, sometimes called double extortion, and it does not require encrypting a single file to be effective. The leverage is the threat of publication.
In MBI’s case, the institute disclosed the intrusion in June and, by its account, addressed the underlying vulnerability and engaged external cybersecurity experts. What it evidently did not do was meet ShinyHunters’ financial demand. When the deadline passed, the group followed through and published the stolen data — the standard consequence in a pay-or-leak scheme when negotiations fail.
That sequence is a reminder that patching the hole after the fact does nothing to recover data already stolen. Once exfiltration has occurred, the victim’s leverage is gone; the choice narrows to paying a criminal group with no obligation to delete anything, or accepting publication. Neither is a good outcome, and law enforcement generally discourages payment precisely because it funds the next attack.
Who ShinyHunters are
ShinyHunters is not a new name. The group has spent years running high-volume data-theft-and-extortion campaigns, and its victim list reads like a tour of well-known brands. It has previously targeted Salesforce, Carnival, and Pitney Bowes, among others, and has been linked to a large-scale campaign against Oracle PeopleSoft deployments that affected more than 100 organizations.
That pattern is instructive. ShinyHunters tends to exploit widely deployed enterprise software and misconfigured systems rather than crafting bespoke attacks against single targets. The approach scales: find one exploitable weakness in a platform many organizations use, then work through the list. Institutions that assume they are too small or too obscure to be worth attacking misunderstand the economics — for a group operating at this volume, an under-defended college is simply another entry in the queue.
The education and nonprofit sectors are particularly exposed to this model. They hold rich personal data on students, donors, and alumni, often across aging systems, and they typically run leaner security budgets than the corporations that make bigger headlines. That combination — valuable data, thinner defenses — is exactly what a volume operator looks for.
What victims should do
Anyone who has studied at, donated to, or otherwise interacted with Moody Bible Institute should assume their personal details may be in the leaked set and act accordingly. MBI has advised affected individuals to monitor their accounts and to consider credit freezes and fraud alerts — sound baseline guidance.
Beyond that, the exposed fields — names, dates of birth, addresses, phone numbers — are precisely the ingredients used to build convincing phishing and social-engineering attacks. Victims should treat unexpected emails, calls, or texts referencing MBI, donations, or account issues with heightened suspicion, and should never act on urgent requests to click a link or share credentials. Enabling multi-factor authentication on important accounts remains one of the most effective defenses against the credential-stuffing that often follows a leak of this kind.
For organizations watching from the sidelines, the lesson is structural, not incidental. This breach is the latest in a run of large-scale exposures we have tracked, from the AssuranceAmerica breach affecting 7 million people to the McHire chatbot leak that exposed up to 64 million job seekers. The common thread is not sophistication — it is basic hygiene failing at scale. Adopting a zero-trust security posture, minimizing the personal data retained in the first place, and rehearsing an incident-response plan before an intrusion occurs are what separate a contained event from a 2.3-million-record disaster.
What it means
The Moody Bible Institute breach is a small institution’s version of a problem now hitting organizations of every size, and its lessons generalize.
For victims, the exposure is durable. Unlike a stolen password, a date of birth or home address cannot be reset. Data that is now in Have I Been Pwned and circulating among criminal buyers will fuel phishing and identity-theft attempts for years, not weeks. The practical response is sustained vigilance — credit monitoring, freezes, and skepticism toward unsolicited contact — rather than a one-time cleanup.
For the education and nonprofit sector, this is a warning shot. Groups like ShinyHunters have industrialized the targeting of data-rich, security-poor organizations. Schools, colleges, and charities that treat cybersecurity as an IT afterthought are betting that they will not be next, and the odds on that bet are getting worse. Regulators and class-action lawyers are already circling breaches of this size, which means the financial cost of underinvestment is rising even for institutions that never pay a ransom.
For everyone, the pay-or-leak model is the story to understand. The most important detail in this incident is that encryption never had to enter the picture. The threat was publication, and once the data was stolen the outcome was largely out of MBI’s hands. That shifts the entire defensive calculus toward prevention and data minimization: the only reliable way to avoid a pay-or-leak crisis is to make sure the attacker never gets the data — or that there is far less of it to take when they do.
Tagged
Keep reading
Chisato · · 5 min read Kudankulam Nuclear Plant Data Breach: What Leaked
Ransomware group World Leaks published 19,000 files tied to India's Kudankulam nuclear plant, leaked via contractor Reliance and data host Yotta.
Chisato · · 6 min read Metabase Zero-Day (CVSS 10.0): SQL Injection Explained
A CVSS 10.0 SQL injection zero-day in Metabase was exploited in the wild to steal database credentials. Affected versions, the fix, and what it means.
Chisato · · 6 min read Amgen Data Breach: Patient PHI Stolen From Cloud Vendors
Biotech giant Amgen disclosed a material breach in an SEC filing: attackers exfiltrated patient health data and proprietary files from third-party cloud.