Were you recently affected by a data breach?

Temple Adat Shalom Sisterhood Data Breach

Temple Adat Shalom Sisterhood in Poway, California, notified California residents that a former volunteer misused mailing list data collected for its Mah Jongg tournaments and card sales, using it without permission for personal advertising campaigns even after being told to stop.

Temple Adat Shalom Sisterhood
Date of Breach: January 2026 (recurring misuse through July 2026)
CAU logo

Who was affected:

Clients of Temple Adat Shalom Sisterhood

Impacted Data:

Names, email addresses, phone numbers, physical addresses, tournament/card-sale activity preference

Temple Adat Shalom Sisterhood, part of Temple Adat Shalom in Poway, California, has notified affected individuals that personal information collected for its Mah Jongg tournament registrations and National Mah Jongg League card sales was accessed and misused by a former volunteer, who used the data without authorization for personal gain even after being asked to stop.

Organizations that collect contact information from members, registrants, and program participants take on a responsibility to safeguard that data and to ensure only authorized individuals can access or use it for legitimate purposes.

Temple Adat Shalom Sisterhood’s Data Breach Investigation

According to a notification letter filed with the California Attorney General, Temple Adat Shalom Sisterhood discovered that a former volunteer who had helped run its Mah Jongg tournament had accessed spreadsheets containing registrant contact information compiled over several years. The volunteer used this data, without the knowledge or permission of Sisterhood or Temple leadership, to send unauthorized marketing emails. The first of these campaigns used Temple Adat Shalom’s own name and logos, which the letter states was done without Temple or Sisterhood leadership’s knowledge, creating the appearance that the outreach was officially sanctioned by the organization. A second campaign followed the same week, this time sent from the former volunteer’s personal email account rather than any Temple-affiliated address.

Sisterhood and Temple leadership say they only learned of the situation after receiving numerous phone calls and emails from people who had received the unsolicited advertising and wanted to know why their information had been used this way. Once alerted, leadership contacted the former volunteer directly and demanded that the use of Sisterhood data and Temple resources stop immediately. The volunteer agreed to that request at the time.

The matter resurfaced in July 2026, when a third targeted advertising campaign went out to individuals on the same mailing list. Sisterhood leadership again learned of it through complaints from recipients, and concluded that the former volunteer had never actually deleted the data as previously agreed and had continued to retain it. In response, the Sisterhood’s Board of Trustees was briefed, and the Temple President sent the former volunteer a formal written cease-and-desist letter demanding that all copies of the data be deleted from every device, account, and storage location, along with written confirmation that the deletion had occurred.

Incidents involving insider misuse of member or registrant data, rather than an external hack, are a recurring risk for community and nonprofit organizations that rely on volunteers to manage sign-up sheets, spreadsheets, and mailing lists. Because volunteers often have broad, informal access to this kind of information as part of running an event, organizations frequently lack the kind of access controls, data retention limits, or offboarding procedures that a larger institution might use to prevent a former volunteer from retaining data indefinitely. When that data includes direct contact details, it can be repurposed for unrelated advertising or solicitation long after the original program has ended, as appears to have happened here.

Volunteer-run organizations rarely have a formal data governance policy spelling out who may access member and registrant contact lists, how long that data can be retained, or what happens to it when a volunteer’s role ends. Unlike an employee, a volunteer typically is not bound by a signed confidentiality agreement or subject to a formal offboarding checklist that revokes system access and requires the return or deletion of any exported spreadsheets. That gap can leave an organization with little practical recourse beyond an informal request to stop using the data, which is exactly the kind of request that, as described here, was not ultimately honored.

The specific combination of data involved in this incident, full names paired with email addresses, phone numbers, and physical addresses, is enough on its own to enable unwanted solicitation, spam, and targeted advertising, even without more sensitive identifiers like Social Security numbers or financial account information. When someone outside an organization retains this kind of contact list after their access should have ended, affected individuals can end up receiving communications that appear, at first glance, to be legitimate outreach from a trusted community group, exactly the concern raised by the branded first email campaign described in the notification letter. That risk of confusion between authorized and unauthorized use of an organization’s name is one reason cease-and-desist demands like the one described here are an important, if imperfect, tool for community organizations trying to protect the people on their mailing lists.

When Did This Breach Occur?

The notification letter, dated July 18, 2026, states that the underlying data set included all individuals listed in Sisterhood spreadsheets created up through Sunday, January 18, 2026. The first two unauthorized advertising campaigns took place in January 2026, shortly after that data was compiled, and the former volunteer agreed at that time to stop using the information. A third, separate advertising campaign using the same data occurred in July 2026, which is what prompted the Temple’s formal cease-and-desist letter and the notification to affected individuals.

What Information Was Breached?

The Sisterhood states that the information involved included each affected person’s first and last name, email address, cell phone number or landline, physical address, and their recorded activity preference, meaning whether they had signed up for Mah Jongg tournaments, National Mah Jongg League card purchases, or both. The Sisterhood says it does not sell or share this information with outside parties, and that the exposure resulted solely from the former volunteer’s retention and reuse of data gathered through legitimate tournament and card-sale registration over multiple years.

What You Can Do

If you registered for a Temple Adat Shalom Sisterhood Mah Jongg tournament or purchased a National Mah Jongg League card through the Sisterhood, and you received unsolicited advertising emails referencing these events, you were likely among those affected. Consider taking these steps:

  • Reply to any notification email to specify whether you want to be removed from Mah Jongg-related emails, card sale communications, tournament communications, or all of the above.
  • Watch for any further unsolicited contact referencing your tournament or card-sale registration, and avoid clicking links in messages from senders you do not recognize.
  • Consider using a unique email address or phone number for community group sign-ups going forward, making it easier to trace where unwanted contact originates.
  • Keep a copy of the notification letter and any suspicious follow-up communications in case they are needed later.

File a Data Breach Lawsuit Against Temple Adat Shalom Sisterhood

Individuals whose contact information was retained and reused without permission after registering for a community event may have legal options, particularly where an organization was told about the misuse but the data was not deleted as promised. An attorney experienced in data breach and privacy cases can help you understand what protections may apply to your situation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Suspicious activity detected June 21, 2026; affected individuals notified starting August 13, 2026
Date of Breach: Network access began January 16, 2025; discovered by the Practice and disclosed to affected individuals starting August 13, 2026
Date of Breach: January 2026 (recurring misuse through July 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.