Pension Fund of the Christian Church reported two incidents: unauthorized access to a legacy server containing member PII (names, DOB, SSN, PIN) discovered on Dec 11, 2017, and theft of a password-protected laptop containing similar data on Dec 18, 2017. The server access occurred on Nov 9, 2017. No evidence of data exfiltration from the server was found. The organization engaged forensic investigators, contacted law enforcement, and offered one year of credit monitoring.