Diocese of Las Vegas disclosed a data breach affecting parishioners and donors

Organization
Diocese of Las Vegas
Exploit
Hacking
Industry
Religious Organization

The Diocese of Las Vegas said in late April 2023 that it had detected a cybersecurity incident affecting its information technology systems on March 12. The diocese described the data involved as sensitive but did not itemize the categories of information exposed.

According to the diocese, the records at issue concerned volunteers, parishioners, donors and other people connected to the church. It said employee payroll and benefits information and Catholic Stewardship Appeal data were not affected because those records were held on separate cloud-based servers.

The diocese notified law enforcement and brought in third-party cybersecurity experts to assess, contain and remediate the incident. It said its investigation had found no instances of fraud or identity theft resulting from the breach, and that it was issuing notice out of an abundance of caution.

A dedicated call center was set up for people with questions, and the diocese said it had reviewed and enhanced its data security policies and procedures to reduce the likelihood of a repeat. As of the reporting date no attacker had been publicly identified, no ransom demand had been described, and the number of people whose information was involved had not been disclosed.

Sources