Chapel Hill Presbyterian Church identified an external system breach, or hacking, which occurred on January 30, 2026. The church discovered this breach on February 26, 2026, and subsequently reported it to regulators and began notifying affected individuals on March 23, 2026.
The breach involved the compromise of names and other personal identifiers for approximately 1,000 individuals. Identity theft protection services, including credit monitoring, were offered for 12 months. The specific types of "other personal identifiers" have not been publicly detailed. While 350 GB+ of data, including mail servers and databases, were compromised, the specific data types involved beyond names and other personal identifiers remain unclear.
Details often emerge over time as investigations continue and notifications are processed. Affected individuals may receive further information as it becomes available.