Temple Adat Shalom Sisterhood, part of Temple Adat Shalom in Poway, California, has notified affected individuals that personal information collected for its Mah Jongg tournament registrations and National Mah Jongg League card sales was accessed and misused by a former volunteer, who used the data without authorization for personal gain even after being asked to stop.
Organizations that collect contact information from members, registrants, and program participants take on a responsibility to safeguard that data and to ensure only authorized individuals can access or use it for legitimate purposes.
Temple Adat Shalom Sisterhood’s Data Breach Investigation
According to a notification letter filed with the California Attorney General, Temple Adat Shalom Sisterhood discovered that a former volunteer who had helped run its Mah Jongg tournament had accessed spreadsheets containing registrant contact information compiled over several years. The volunteer used this data, without the knowledge or permission of Sisterhood or Temple leadership, to send unauthorized marketing emails. The first of these campaigns used Temple Adat Shalom’s own name and logos, which the letter states was done without Temple or Sisterhood leadership’s knowledge, creating the appearance that the outreach was officially sanctioned by the organization. A second campaign followed the same week, this time sent from the former volunteer’s personal email account rather than any Temple-affiliated address.
Sisterhood and Temple leadership say they only learned of the situation after receiving numerous phone calls and emails from people who had received the unsolicited advertising and wanted to know why their information had been used this way. Once alerted, leadership contacted the former volunteer directly and demanded that the use of Sisterhood data and Temple resources stop immediately. The volunteer agreed to that request at the time.
The matter resurfaced in July 2026, when a third targeted advertising campaign went out to individuals on the same mailing list. Sisterhood leadership again learned of it through complaints from recipients, and concluded that the former volunteer had never actually deleted the data as previously agreed and had continued to retain it. In response, the Sisterhood’s Board of Trustees was briefed, and the Temple President sent the former volunteer a formal written cease-and-desist letter demanding that all copies of the data be deleted from every device, account, and storage location, along with written confirmation that the deletion had occurred.
Incidents involving insider misuse of member or registrant data, rather than an external hack, are a recurring risk for community and nonprofit organizations that rely on volunteers to manage sign-up sheets, spreadsheets, and mailing lists. Because volunteers often have broad, informal access to this kind of information as part of running an event, organizations frequently lack the kind of access controls, data retention limits, or offboarding procedures that a larger institution might use to prevent a former volunteer from retaining data indefinitely. When that data includes direct contact details, it can be repurposed for unrelated advertising or solicitation long after the original program has ended, as appears to have happened here.
Volunteer-run organizations rarely have a formal data governance policy spelling out who may access member and registrant contact lists, how long that data can be retained, or what happens to it when a volunteer’s role ends. Unlike an employee, a volunteer typically is not bound by a signed confidentiality agreement or subject to a formal offboarding checklist that revokes system access and requires the return or deletion of any exported spreadsheets. That gap can leave an organization with little practical recourse beyond an informal request to stop using the data, which is exactly the kind of request that, as described here, was not ultimately honored.
The specific combination of data involved in this incident, full names paired with email addresses, phone numbers, and physical addresses, is enough on its own to enable unwanted solicitation, spam, and targeted advertising, even without more sensitive identifiers like Social Security numbers or financial account information. When someone outside an organization retains this kind of contact list after their access should have ended, affected individuals can end up receiving communications that appear, at first glance, to be legitimate outreach from a trusted community group, exactly the concern raised by the branded first email campaign described in the notification letter. That risk of confusion between authorized and unauthorized use of an organization’s name is one reason cease-and-desist demands like the one described here are an important, if imperfect, tool for community organizations trying to protect the people on their mailing lists.
When Did This Breach Occur?
The notification letter, dated July 18, 2026, states that the underlying data set included all individuals listed in Sisterhood spreadsheets created up through Sunday, January 18, 2026. The first two unauthorized advertising campaigns took place in January 2026, shortly after that data was compiled, and the former volunteer agreed at that time to stop using the information. A third, separate advertising campaign using the same data occurred in July 2026, which is what prompted the Temple’s formal cease-and-desist letter and the notification to affected individuals.
What Information Was Breached?
The Sisterhood states that the information involved included each affected person’s first and last name, email address, cell phone number or landline, physical address, and their recorded activity preference, meaning whether they had signed up for Mah Jongg tournaments, National Mah Jongg League card purchases, or both. The Sisterhood says it does not sell or share this information with outside parties, and that the exposure resulted solely from the former volunteer’s retention and reuse of data gathered through legitimate tournament and card-sale registration over multiple years.
What You Can Do
If you registered for a Temple Adat Shalom Sisterhood Mah Jongg tournament or purchased a National Mah Jongg League card through the Sisterhood, and you received unsolicited advertising emails referencing these events, you were likely among those affected. Consider taking these steps:
- Reply to any notification email to specify whether you want to be removed from Mah Jongg-related emails, card sale communications, tournament communications, or all of the above.
- Watch for any further unsolicited contact referencing your tournament or card-sale registration, and avoid clicking links in messages from senders you do not recognize.
- Consider using a unique email address or phone number for community group sign-ups going forward, making it easier to trace where unwanted contact originates.
- Keep a copy of the notification letter and any suspicious follow-up communications in case they are needed later.
File a Data Breach Lawsuit Against Temple Adat Shalom Sisterhood
Individuals whose contact information was retained and reused without permission after registering for a community event may have legal options, particularly where an organization was told about the misuse but the data was not deleted as promised. An attorney experienced in data breach and privacy cases can help you understand what protections may apply to your situation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.