Were you recently affected by a data breach?

Goodwill Industries of Greater Grand Rapids, Inc Data Breach

Goodwill Industries of Greater Grand Rapids notified people that an unauthorized party obtained files containing personal information, per a Massachusetts AG filing. Here is what is known.

Goodwill Industries of Greater Grand Rapids, Inc
Date of Breach: Discovered mid-March 2026
CAU logo

Who was affected:

Clients of Goodwill Industries of Greater Grand Rapids, Inc

Impacted Data:

Names combined with other personal data elements (specific types not publicly disclosed)

Goodwill Industries of Greater Grand Rapids, Inc. has notified people that an unauthorized party obtained files from its network and that those files contained some of their personal information, according to a notice filed with the Massachusetts Attorney General’s Office.

Goodwill Industries of Greater Grand Rapids, Inc’s Data Breach Investigation

Goodwill Industries of Greater Grand Rapids, Inc. has notified individuals that an unauthorized third party obtained files from its computer environment, and that those files contained some of their personal information. The company’s notification letter was filed with the Massachusetts Attorney General’s Office as part of its September 2026 listing of data breach notifications, and it is the main public record of what the organization has said about the incident.

According to the letter, the organization learned of unauthorized activity in its network in mid-March 2026. It brought in outside cybersecurity experts to investigate. That investigation later determined that an unauthorized party had acquired files from the environment. Goodwill then identified which files were affected and hired a data-review firm to analyze their contents, a step that is often the slowest part of a breach response because it means combing through large volumes of documents to work out who is named in them and what was exposed.

The incident was not invisible to the public while this was happening. In late March 2026, the organization posted a statement on its own website saying it had experienced an attack that disrupted part of its network, affecting the resources used to run its local stores. It said its systems do not store credit card data, and that stores were operating on a cash-only basis while the point-of-sale system was rebuilt. It also said the incident did not affect Goodwill stores or organizations in other communities.

The notification letter says the organization has since worked to make sure it has accurate contact information for the people who need to be notified. It reports that it informed law enforcement and that the notice was not delayed by a law enforcement request. It also says it worked with third-party experts to address the event, investigate the unauthorized activity, and further secure its systems.

As a protective step, Goodwill is offering recipients a complimentary membership in Epiq’s Privacy Solutions ID 1B credit monitoring service, at the Plus level. The letter explains that recipients enroll online with a personal activation code before a stated enrollment deadline, and it gives a phone number for questions about the incident as well as a separate help line for enrollment support.

Several details remain unpublished. The filing as posted by the state is the generic mail-merge template, so the field listing each person’s exposed data elements, the length of the monitoring membership, and the enrollment deadline all appear as blank placeholders rather than real values. The organization has not publicly stated a universal list of the data types involved, and the Massachusetts listing reflects only the number of Massachusetts residents notified, not the total number of people affected across all states.

Some general context helps explain why an incident like this matters. Retail and workforce-service nonprofits commonly hold records about employees, job applicants, program participants, and donors. Those records can include names, contact details, government identification numbers, and payroll or benefits information. Files taken from a network, as opposed to systems merely being disrupted, can be misused long after the original disruption has ended, because stolen documents do not expire the way a service outage does. This is general industry context and is not a confirmed statement about which records were involved in this particular incident.

State breach notification laws generally require an organization to notify affected people and regulators within a set period after it determines that personal information was acquired. The months between a mid-March discovery and a fall notice are consistent with the lengthy file-review process described in the letter. A gap like that is common in incidents where the organization must first work out who was affected, and it does not by itself say anything about how serious the exposure was for any one person.

Anyone who received this letter should read it closely, keep the envelope and activation code, and enroll in the monitoring before the deadline if they want the service. Free monitoring can help spot new accounts opened in your name, but it does not undo an exposure, and it is not a substitute for taking your own protective steps.

The sections below cover the timing of the incident as currently known, the types of information that may be involved, practical steps you can take now, and how to learn whether you may have legal options after receiving a notice from Goodwill Industries of Greater Grand Rapids.

When Did This Breach Occur?

The notification letter states that the organization learned of unauthorized activity in its network in mid-March 2026. A public statement posted on March 27, 2026 confirms that the organization was dealing with a network attack by that time.

The date on which the files were actually taken is not stated in the filing. After the initial discovery, the organization investigated, determined that files had been acquired, and then reviewed those files to identify the people named in them before sending notices. The Massachusetts listing places the notice in September 2026.

If you received a letter, check its date and any dates mentioned in it. Those details, along with the call center number in the letter, are the best way to learn more about your own situation.

What Information Was Breached?

Goodwill’s letter says the impacted files contained some of each recipient’s personal information, with the specific data elements listed individually in each person’s copy. The sample filed with the state leaves that list as a blank placeholder, and the organization has not published one elsewhere that this page can verify.

Because the specific data types are unconfirmed, it is wise to assume that any identifier tied to your name could be at risk, particularly if you have worked for, applied to, or received services from the organization. That can include contact details, government identification numbers, or financial information. Your own letter is the only reliable source for what applies to you.

The organization offered credit monitoring with identity protection features, a type of package companies usually provide when Social Security numbers or similar identifiers may be involved. That is an observation about the type of service offered, not a confirmation of what data was exposed.

What You Can Do

Start by reading your notice carefully and enrolling in any identity monitoring offered before the deadline printed in your letter. Keep your activation code in a safe place.

Consider placing a free security freeze on your credit file with Equifax, Experian, and TransUnion. A freeze stops new credit from being opened in your name without your authorization. You can also place a free fraud alert, which requires businesses to verify your identity before extending credit.

Request your free credit reports at annualcreditreport.com and review them for accounts or inquiries you do not recognize. Check bank and card statements regularly, and report anything unfamiliar to the institution right away. If you believe your identity has been misused, you can report it to the Federal Trade Commission at IdentityTheft.gov and file a police report.

Be cautious about unexpected calls, texts, and emails that mention the incident or ask you to confirm personal details. Scammers often use news of a breach to make their messages look legitimate. Use the phone number printed in your official notice rather than one supplied by an unsolicited message.

File a Data Breach Lawsuit Against Goodwill Industries of Greater Grand Rapids, Inc

Receiving a data breach notice can mean you have legal options, particularly when sensitive personal information may have been exposed because of a company’s security practices. A lawyer can review your notice, explain how the facts apply to you, and tell you whether joining a class action makes sense.

Class actions let many people with similar claims pursue them together, which can make it practical to hold a company accountable when individual losses are small or hard to prove. Claims in breach cases often focus on whether the company took reasonable steps to protect the information it held and whether it notified people promptly.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed (patient notifications began September 25, 2026)
Date of Breach: August 3, 2026
Date of Breach: Not publicly disclosed (notification letters dated September 25, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.