Goodwill Industries of Greater Grand Rapids, Inc. has notified people that an unauthorized party obtained files from its network and that those files contained some of their personal information, according to a notice filed with the Massachusetts Attorney General’s Office.
Goodwill Industries of Greater Grand Rapids, Inc’s Data Breach Investigation
Goodwill Industries of Greater Grand Rapids, Inc. has notified individuals that an unauthorized third party obtained files from its computer environment, and that those files contained some of their personal information. The company’s notification letter was filed with the Massachusetts Attorney General’s Office as part of its September 2026 listing of data breach notifications, and it is the main public record of what the organization has said about the incident.
According to the letter, the organization learned of unauthorized activity in its network in mid-March 2026. It brought in outside cybersecurity experts to investigate. That investigation later determined that an unauthorized party had acquired files from the environment. Goodwill then identified which files were affected and hired a data-review firm to analyze their contents, a step that is often the slowest part of a breach response because it means combing through large volumes of documents to work out who is named in them and what was exposed.
The incident was not invisible to the public while this was happening. In late March 2026, the organization posted a statement on its own website saying it had experienced an attack that disrupted part of its network, affecting the resources used to run its local stores. It said its systems do not store credit card data, and that stores were operating on a cash-only basis while the point-of-sale system was rebuilt. It also said the incident did not affect Goodwill stores or organizations in other communities.
The notification letter says the organization has since worked to make sure it has accurate contact information for the people who need to be notified. It reports that it informed law enforcement and that the notice was not delayed by a law enforcement request. It also says it worked with third-party experts to address the event, investigate the unauthorized activity, and further secure its systems.
As a protective step, Goodwill is offering recipients a complimentary membership in Epiq’s Privacy Solutions ID 1B credit monitoring service, at the Plus level. The letter explains that recipients enroll online with a personal activation code before a stated enrollment deadline, and it gives a phone number for questions about the incident as well as a separate help line for enrollment support.
Several details remain unpublished. The filing as posted by the state is the generic mail-merge template, so the field listing each person’s exposed data elements, the length of the monitoring membership, and the enrollment deadline all appear as blank placeholders rather than real values. The organization has not publicly stated a universal list of the data types involved, and the Massachusetts listing reflects only the number of Massachusetts residents notified, not the total number of people affected across all states.
Some general context helps explain why an incident like this matters. Retail and workforce-service nonprofits commonly hold records about employees, job applicants, program participants, and donors. Those records can include names, contact details, government identification numbers, and payroll or benefits information. Files taken from a network, as opposed to systems merely being disrupted, can be misused long after the original disruption has ended, because stolen documents do not expire the way a service outage does. This is general industry context and is not a confirmed statement about which records were involved in this particular incident.
State breach notification laws generally require an organization to notify affected people and regulators within a set period after it determines that personal information was acquired. The months between a mid-March discovery and a fall notice are consistent with the lengthy file-review process described in the letter. A gap like that is common in incidents where the organization must first work out who was affected, and it does not by itself say anything about how serious the exposure was for any one person.
Anyone who received this letter should read it closely, keep the envelope and activation code, and enroll in the monitoring before the deadline if they want the service. Free monitoring can help spot new accounts opened in your name, but it does not undo an exposure, and it is not a substitute for taking your own protective steps.
The sections below cover the timing of the incident as currently known, the types of information that may be involved, practical steps you can take now, and how to learn whether you may have legal options after receiving a notice from Goodwill Industries of Greater Grand Rapids.
When Did This Breach Occur?
The notification letter states that the organization learned of unauthorized activity in its network in mid-March 2026. A public statement posted on March 27, 2026 confirms that the organization was dealing with a network attack by that time.
The date on which the files were actually taken is not stated in the filing. After the initial discovery, the organization investigated, determined that files had been acquired, and then reviewed those files to identify the people named in them before sending notices. The Massachusetts listing places the notice in September 2026.
If you received a letter, check its date and any dates mentioned in it. Those details, along with the call center number in the letter, are the best way to learn more about your own situation.
What Information Was Breached?
Goodwill’s letter says the impacted files contained some of each recipient’s personal information, with the specific data elements listed individually in each person’s copy. The sample filed with the state leaves that list as a blank placeholder, and the organization has not published one elsewhere that this page can verify.
Because the specific data types are unconfirmed, it is wise to assume that any identifier tied to your name could be at risk, particularly if you have worked for, applied to, or received services from the organization. That can include contact details, government identification numbers, or financial information. Your own letter is the only reliable source for what applies to you.
The organization offered credit monitoring with identity protection features, a type of package companies usually provide when Social Security numbers or similar identifiers may be involved. That is an observation about the type of service offered, not a confirmation of what data was exposed.
What You Can Do
Start by reading your notice carefully and enrolling in any identity monitoring offered before the deadline printed in your letter. Keep your activation code in a safe place.
Consider placing a free security freeze on your credit file with Equifax, Experian, and TransUnion. A freeze stops new credit from being opened in your name without your authorization. You can also place a free fraud alert, which requires businesses to verify your identity before extending credit.
Request your free credit reports at annualcreditreport.com and review them for accounts or inquiries you do not recognize. Check bank and card statements regularly, and report anything unfamiliar to the institution right away. If you believe your identity has been misused, you can report it to the Federal Trade Commission at IdentityTheft.gov and file a police report.
Be cautious about unexpected calls, texts, and emails that mention the incident or ask you to confirm personal details. Scammers often use news of a breach to make their messages look legitimate. Use the phone number printed in your official notice rather than one supplied by an unsolicited message.
File a Data Breach Lawsuit Against Goodwill Industries of Greater Grand Rapids, Inc
Receiving a data breach notice can mean you have legal options, particularly when sensitive personal information may have been exposed because of a company’s security practices. A lawyer can review your notice, explain how the facts apply to you, and tell you whether joining a class action makes sense.
Class actions let many people with similar claims pursue them together, which can make it practical to hold a company accountable when individual losses are small or hard to prove. Claims in breach cases often focus on whether the company took reasonable steps to protect the information it held and whether it notified people promptly.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.