HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Moody Bible Institute
bd_3972d2d51525b0d4 · schema v1 · pii pii-v1
Full breach record for Moody Bible Institute →The Moody Bible Institute of Chicago experienced a data breach on June 12, 2026, caused by a vulnerability in a software application commonly used by educational institutions. An external actor exploited this vulnerability to illegally acquire files containing names and other personal information. The organization detected unusual activity on the same day, engaged a forensic firm, notified law enforcement, and patched the vulnerability. Affected individuals are offered one year of complimentary identity monitoring.
California clockDiscovered Jun 12, 2026 → Notified Jul 23, 202641d ✗ CA 30-day late6 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626988
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 23, 2026
- Raw hash
- 0acbfe780d19a6cf5e4b1b32e2749065ff4e6f00b38375fdea06b3414cde9aad
Reporting entity
- Name
- Moody Bible Institutenorm: moody bible institute
- Domain
- moodybible.org
Victim entity
- Name
- Moody Bible Institutenorm: moody bible institute
- Domain
- moodybible.org
Incident
- Discovered
- Jun 12, 2026
- Materiality determined
- —
- Notification sent
- Jul 23, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- CA 30-day late · 41dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 12, 2026→ Notified: Jul 23, 202641d 30 calendar days CA 30-day late California Consumers notified: Jul 23, 2026→ AG copy submitted: Jul 23, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.