A 137-year-old Bible college just confirmed one of the largest nonprofit data breaches of 2026.

Moody Bible Institute disclosed that ShinyHunters compromised 2.3 million records — donor financial details, student records, and decades of alumni data — and leaked them. The same week, the group also hit Abbott Laboratories. Nonprofits and healthcare giants, same extortion crew, same playbook.
WHAT ACTUALLY HAPPENED
Moody confirmed the incident after ShinyHunters published stolen records rather than negotiating quietly. The dataset spans generations: alumni going back decades, current students, and donors whose financial and contact information sat in institutional systems that were never built to withstand a targeted extortion campaign.
ShinyHunters did not stop at Moody. Abbott Laboratories was hit in the same window — a pattern this group has run repeatedly through 2026: identify organizations with large, poorly segmented data stores, exfiltrate at scale, then extort with public leaks as leverage instead of relying on encryption alone.
WHY NONPROFITS ARE THE SOFT TARGET
Educational and religious institutions sit on exactly the data extortion crews want — donor payment details, decades of PII, alumni networks — with security budgets sized for a fraction of that risk. Legacy systems accumulate data for decades because nobody owns the deletion decision. Attackers know this. A 137-year-old institution's data retention policy was written for a paper-records era, not a breach-economy one.
The lesson extends past faith-based nonprofits: any organization holding long-tail historical PII — universities, professional associations, membership orgs, alumni networks — carries this same exposure and rarely budgets for it. Attackers do not need a zero-day when a decade of unsegmented CRM exports and donor CSVs sit one compromised credential away.
WHAT TO DO NOW
AUDIT DATA RETENTION, NOT JUST ACCESS CONTROL — data you deleted five years ago cannot be exfiltrated today; retention policy is a security control.
SEGMENT DONOR AND FINANCIAL DATA FROM GENERAL SYSTEMS — a single flat database spanning decades is a single point of catastrophic failure.
ASSUME LEAK-FIRST EXTORTION, NOT JUST ENCRYPTION — ShinyHunters' model is publish-to-pressure; backups alone do not neutralize this threat.
TREAT LEGACY / NONPROFIT INFRASTRUCTURE AS HIGH-VALUE — attackers already have; your budget should follow their targeting logic, not your org chart.
Attackers do not care how long your institution has existed. They care how long your data has sat unsegmented.
Does your organization know exactly how old the oldest record in your donor or alumni database is?