The Faith and Politics Institute, a Washington, D.C. nonprofit that works with political leaders, has notified people of a security incident that may affect the privacy of some of their information. Its notice letter is dated October 5, 2026, and offers 24 months of free credit monitoring.
The Faith and Politics Institute’s Data Breach Investigation
The Faith and Politics Institute is a 501(c)(3) nonprofit organization based in Washington, D.C. that serves members of Congress, national political leaders and senior congressional staff. An organization with that kind of network keeps contact records, event and program files and employment records, and those files can include sensitive personal details.
According to the notice letter, which is titled Notice of Security Incident and dated October 5, 2026, the institute experienced a recent incident that may affect the privacy of some of the recipient’s information. The letter says there is no indication of any actual or attempted misuse of that information at this time. The letter was filed with the Massachusetts state government, which posts breach notification letters it receives.
The letter is unusually short on specifics. It says that, because of requirements imposed by Massachusetts law, the institute is unable to provide further details about the nature of the event in the letter itself, and it directs people to a dedicated assistance line for more information. The filed copy is a template with the recipient’s name and address left as placeholders, and the letter does not state what type of incident occurred, when it happened or what data was involved.
The letter says that, on learning of the incident, the institute took immediate steps to secure its environment and began an investigation to understand the nature and scope of what happened. It says it is reviewing its policies, procedures and processes for storing and accessing sensitive information to reduce the likelihood of a similar incident.
As a precaution, the institute is providing 24 months of complimentary credit monitoring and identity restoration services through IDX. People who receive the letter enroll using a code printed on it, either through a QR code or the IDX website. The letter lists an enrollment deadline in early January 2027, although the header and the body of the letter state slightly different dates, so anyone who receives it should act well before the earlier date.
No count of affected people has been published in the sources reviewed for this page, and the types of information involved have not been disclosed. Readers should not assume any particular data types were exposed. A notice of this kind commonly goes to people whose information the organization holds, such as current and former employees, program participants and contacts, but the letter itself does not say who was notified.
Notice letters are normally the first reliable source of specifics for each person. Keep any letter you receive along with its enrollment code, and call the dedicated assistance line to ask what information of yours was involved. Because the letter itself does not describe the data, asking directly is the most reliable way to find out.
Organizations that hold personal information are generally expected to safeguard it with reasonable measures such as access limits, strong authentication, monitoring for unusual activity and keeping sensitive data only as long as it is needed. If you received this notice, there is no need to assume your information was misused, but it is sensible to take the protective steps the letter describes.
When Did This Breach Occur?
The notice letter is dated October 5, 2026. It does not state when the incident occurred or when the institute discovered it, so the dates of the underlying events have not been confirmed. It describes the incident only as recent.
What Information Was Breached?
The notice letter does not say what types of information were involved. It says only that the incident may impact the privacy of some of the recipient’s information and that Massachusetts law limits the details the institute can include. The institute says there is no indication of actual or attempted misuse. Call the assistance line listed in the letter for specifics about your own information.
What You Can Do
If you received a notice from The Faith and Politics Institute, consider these steps:
- Keep the letter and your enrollment code, and enroll in the free IDX credit monitoring before the deadline listed in the letter.
- Call the dedicated assistance line in the letter and ask what information of yours was involved.
- Place a free fraud alert on your credit file, or consider a credit freeze, with Equifax, Experian and TransUnion.
- Check your credit reports for free at annualcreditreport.com and review account statements for anything you do not recognize.
- Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against The Faith and Politics Institute
If you received a notice about this incident, or believe your personal information was exposed, you may have legal options. Organizations that hold personal information are expected to safeguard it, and a class action can help hold them accountable when they fail to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.