Website Security Notice

Last Updated: July 25, 2026

We recently identified and removed malicious code on the Baptist Standard website. The code has been completely removed, site caches have been cleared, and additional server-level reviews confirm the website is operating securely.

Based on our investigation:

  • Payment Information Was Not Accessed: Payment fields on the website are processed through Stripe Elements, which uses an isolated payment environment that the malicious code could not read or access.

  • Usernames & Passwords Were Not Accessed: The malicious code did not execute on the website’s login portal, and login credentials were not exposed.

  • Stored Database Records Were Not Accessed: Stored database records and historical customer files were not downloaded or exfiltrated.

The code was active on the website between February 4, 2026, and July 23, 2026. While active, the code was capable of capturing information typed into standard website form fields at the time of submission (such as names, email addresses, physical addresses, phone numbers, or message text submitted through website forms).

As a precaution, anyone who submitted a form on the website between February 4, 2026, and July 23, 2026, should remain alert for suspicious or unexpected emails, links, or messages.

If we determine that notice under applicable law is required for specific individuals, we will notify affected parties directly as appropriate.