Menu
Browse

Cyber Incident Victim: Goodwill Industries

Date:

Jan 2022

Location:

United States of America

Summary

A nonprofit organization experienced a data breach affecting its e-commerce auction platform, exposing customers' personal contact information including names, email addresses, phone numbers, and mailing addresses. The incident stemmed from a website vulnerability that allowed unauthorized third-party access, though payment card details remained unaffected as they were not stored on the platform's servers. Account credentials were also not compromised during the breach. The organization promptly addressed the security flaw and notified impacted individuals, offering a dedicated contact channel for further inquiries while emphasizing its commitment to safeguarding personal information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 14, 2022, Goodwill publicly disclosed a data breach impacting customers of its ShopGoodwill.com e-commerce auction platform. The nonprofit organization confirmed that unauthorized third parties exploited a vulnerability in the platform’s website, resulting in the exposure of buyers’ personal contact information. According to ShopGoodwill Vice President Ryan Smith, the compromised data included affected individuals’ first and last names, email addresses, phone numbers, and mailing addresses. The breach notification letters clarified that payment card information remained unaffected, as ShopGoodwill does not store such data on its servers. Smith emphasized that while attackers accessed buyer contact details, they did not compromise user accounts on the platform. Goodwill did not specify the exact number of affected individuals or the timeframe during which the vulnerability was actively exploited.

Cyber Incident Image

Upon identifying the issue, Goodwill addressed the vulnerability and secured its systems to prevent further unauthorized access. The organization notified impacted customers directly via breach notification letters, advising them to monitor their personal information for misuse. Smith stated ShopGoodwill’s commitment to safeguarding user data and apologized for any concern caused by the incident. The nonprofit directed individuals with unresolved questions to contact [email protected] and pledged to provide updates if additional relevant information emerged. Goodwill, which reported assisting over 25 million people with disabilities or disadvantages in 2019 and training 230,000 individuals for careers in sectors like IT and healthcare, operates its e-commerce platform alongside a global network of thrift stores. A Goodwill spokesperson declined to comment further when contacted by BleepingComputer on the disclosure date.

Sources
Sources available to members
1 source