2026 Moody Bible Institute — ShinyHunters breach; 2.35M emails published (Jun)
Data compromised
Published breach corpus cited ~2.35M unique email addresses plus names, addresses, phone numbers, and other personal information per breach-intelligence tracking after ShinyHunters data release; actor marketing also claimed 23GB / tens of millions of rows across donor, payroll, and student systems—unverified row totals
Technical writeup
Unverified institution notice but verified published corpus — indexed June 15–29, 2026. ShinyHunters listed Moody Bible Institute (Chicago Christian higher-education institution) on its leak site June 15, 2026, claiming more than 23 gigabytes across enrollment, donor relations, payroll, PeopleSoft communications, Salesforce leads, and student housing systems with a June 18 deadline. After the actor published data, breach-intelligence trackers including XposedOrNot cataloged approximately 2.35 million unique email addresses with associated personal information from the released corpus. Moody Bible Institute had not issued a public confirmation or victim notification at catalog time. BreachHistory uses the published-email count as the headline recordsAffected figure while treating the institute as unconfirmed pending an official notice.
Root cause
ShinyHunters extortion campaign against Moody Bible Institute (moody.edu); actor claimed Oracle PeopleSoft-adjacent access across enrollment, donor, payroll, and communications systems—institute had not confirmed at catalog time
References
- https://www.ransomware.live/id/bW9vZHkuZWR1QHNoaW55aHVudGVycw
- https://www.classaction.org/data-breach-lawsuits/moody-bible-institute-june-2026
- https://www.dexpose.io/shinyhunters-breach-moody-bible-institute/
- https://www.securityweek.com/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters/