Goodwill Industries of Greater Grand Rapids discovered unauthorized network activity in March 2026 and later confirmed an outsider had taken files containing personal information belonging to its clients. The organization notified affected people in September 2026 and is offering free credit monitoring. If you received a notice, enroll in the monitoring service and consider placing a credit freeze right away.
| Company | Goodwill Industries of Greater Grand Rapids, Inc |
|---|---|
| Industry | Non-profit |
| Data Types Exposed | Full Names, Contact Information, Government-Issued Identification Numbers, Financial or Payroll Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Goodwill Industries of Greater Grand Rapids Data Breach?
Goodwill Industries of Greater Grand Rapids has told affected people that an outside party got into its network and pulled files containing personal information. This disclosure appears in a notice the organization filed with the Massachusetts Attorney General’s Office. That filing is currently the clearest public record describing what happened.
According to the notice, the organization first noticed unusual activity on its network in March 2026. Around the same time, Goodwill posted a public statement saying an attack had disrupted parts of its systems. That disruption affected the technology that supports its local retail stores. The organization said its stores do not store credit card numbers, and that locations briefly ran on a cash-only basis while staff rebuilt the point-of-sale system. It also said the disruption was limited to this particular Goodwill and did not reach other Goodwill organizations elsewhere.
After spotting the suspicious activity, Goodwill brought in outside cybersecurity specialists to look into what had happened. That investigation confirmed that an unauthorized party had actually taken files from the network, not simply caused an outage. Because of this, the organization then had to identify exactly which files were involved and who appeared in them. It hired a separate data-review firm to comb through the material, a process that commonly takes months because it involves reading through large volumes of documents individually.
This lengthy review likely explains the gap between the March discovery and the September notification. State breach laws generally require notice within a set window once a company determines personal information was actually taken. A months-long gap is common when an organization must first work out exactly whose data appears in stolen files before it can notify them.
Who was affected?
The notice describes the affected population as clients of Goodwill Industries of Greater Grand Rapids. Because Goodwill runs retail stores and workforce programs, the people connected to this breach could include donors, shoppers, program participants, job applicants, or employees. The notice itself does not spell out which of these groups is involved, so it’s best for anyone connected to the organization to take the notice seriously.
The total number of people affected nationwide has not been publicly disclosed. The Massachusetts filing only reports how many Massachusetts residents were notified, not the full count across every state where affected individuals may live. As a result, the true scope of this incident remains unclear outside of that one state’s figures.
It is also not confirmed whether minors are among those affected. Because Goodwill provides community services beyond simple retail transactions, the incident could touch a wider range of people than a typical retail breach. Anyone who has interacted with this specific Goodwill location, whether as a customer, employee, or program participant, should treat a received notice as relevant to them.
What Information Was Potentially Exposed?
Goodwill’s notification letter states that the impacted files contained personal information specific to each recipient. However, the version of the letter filed with Massachusetts regulators uses a generic template, and the field meant to list each person’s exact exposed data elements was left blank in that public copy. As a result, the precise data types have not been confirmed in the public record.
Based on the nature of services an organization like this provides, the categories of information potentially involved could include the following.
- Full names
- Contact information such as addresses or phone numbers
- Government-issued identification numbers
- Financial or payroll-related information
- Other personal details tied to employment, program participation, or donor records
This list reflects general categories that organizations like this one typically hold, not a confirmed inventory for this specific incident. Your individual notice, if you received one, is the most reliable source for which data elements applied to you personally.
If identification numbers or financial details were part of the exposed files, affected individuals could face a heightened risk of identity theft. Criminals who obtain names paired with government ID numbers can sometimes open new credit lines, file fraudulent tax returns, or apply for loans using someone else’s identity.
Even when only names and contact details are involved, there is still real risk. Scammers frequently use breach notices as bait for targeted phishing attempts, posing as the breached company to trick people into handing over additional sensitive information. Because the exact data types here remain unconfirmed, caution is the safest approach for anyone who received a notice.
What is the company doing?
Once Goodwill determined that files had been taken, it worked with outside cybersecurity experts to investigate the unauthorized activity and strengthen its network defenses. The organization also says it notified law enforcement about the incident. Importantly, the notice states that the investigation was not delayed by any law enforcement request, meaning Goodwill moved through its own review process at its own pace.
As part of its response, Goodwill is offering affected individuals a complimentary membership in Epiq’s Privacy Solutions ID 1B credit monitoring service at the Plus level. Recipients can enroll online using a personal activation code included in their letter. The letter also provides a phone number for questions about the incident, along with a separate help line dedicated to enrollment support.
In addition to these consumer-facing steps, Goodwill filed formal notification with the Massachusetts Attorney General’s Office as part of its September 2026 reporting of data breach incidents. This filing is the primary documented source confirming the organization’s response to date. Beyond what appears in that filing, Goodwill has not publicly released further details about the investigation’s findings.
What Should Affected Individuals Do?
Enroll in Credit Monitoring and Watch Your Accounts
If you received a letter from Goodwill, take time to read it fully and enroll in the offered credit monitoring before any deadline printed in your copy. This service can help flag new accounts or credit inquiries opened in your name without your permission. Keep your personal activation code somewhere safe until you’ve completed enrollment.
Beyond the offered service, it’s wise to check your bank and credit card statements regularly for unfamiliar transactions. Because free monitoring catches new account activity but doesn’t always catch existing account misuse, pairing it with your own statement reviews gives you broader coverage. Report anything suspicious to your financial institution immediately.
Consider a Credit Freeze or Fraud Alert
Because the exact data exposed here hasn’t been confirmed, placing a security freeze with Equifax, Experian, and TransUnion is a reasonable precaution. A freeze blocks new credit accounts from being opened in your name unless you personally lift it first. This step is free and can be reversed whenever you need to apply for credit yourself.
Alternatively, a fraud alert requires businesses to verify your identity before extending new credit. This option is less restrictive than a full freeze but still adds a layer of protection. Either step is worth taking if you’re concerned about identification numbers or financial details being part of the exposed files.
Pull Your Free Credit Reports
You’re entitled to a free credit report from each of the three major bureaus through annualcreditreport.com. Reviewing these reports lets you spot accounts, inquiries, or addresses you don’t recognize. If anything looks unfamiliar, dispute it directly with the bureau and the business involved.
Make this a repeated habit rather than a one-time check. Because stolen files can be misused months or even years after a breach, ongoing vigilance matters more than a single review. Set a recurring reminder to check your reports every few months going forward.
Stay Alert for Phishing Attempts
Scammers often use news of a breach to make fraudulent messages appear legitimate. Be cautious of unexpected calls, texts, or emails referencing this incident or asking you to confirm personal details. Legitimate notices will not ask you to provide sensitive information over email or text.
If you need to verify anything about your notice, use the phone number printed in your official letter rather than contact information from an unsolicited message. This simple habit can prevent you from accidentally giving scammers exactly the information they’re hoping to collect. When in doubt, hang up and call back using a number you’ve verified independently.
Know Your Legal Options
Receiving a breach notice can mean you have legal options, especially if sensitive personal information was involved because of gaps in a company’s security practices. Many affected individuals choose to consult a data breach attorney for a free case evaluation to understand whether joining a class action makes sense for their situation.
Class actions allow people with similar claims to pursue them together, which can make pursuing accountability practical even when individual losses feel small or hard to prove. If you received a notice from Goodwill Industries of Greater Grand Rapids, speaking with an attorney can help clarify your specific rights and any applicable deadlines.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
