What Happened in the Temple Adat Shalom Sisterhood Data Breach?
Temple Adat Shalom Sisterhood, a volunteer-run group connected to Temple Adat Shalom in Poway, California, has confirmed a data breach tied to a former volunteer’s misuse of member contact information. The organization says a person who once helped coordinate its Mah Jongg tournaments kept spreadsheets of registrant details long after their role ended. That data was then used without permission for personal advertising outreach.
According to the notification, unauthorized access to this contact data occurred in January 2026. The former volunteer used the information to send unsolicited marketing emails. One early email campaign even used the Temple’s name and logo, making it appear to be official Temple communication, even though leadership had no knowledge of it.
A second wave of messages followed within the same week. This time, the volunteer sent them from a personal email account instead of one connected to the Temple. As a result, recipients had no clear way of knowing who was truly behind the outreach.
Temple leadership only learned about the situation after fielding a wave of phone calls and emails from confused recipients. Once alerted, they contacted the former volunteer directly and demanded the activity stop. The volunteer agreed at the time, but the matter did not end there.
In July 2026, a third advertising campaign went out using the same list. This time, Sisterhood leadership realized the data had never actually been deleted as promised. In response, the Temple’s Board of Trustees was briefed, and the Temple President issued a formal cease-and-desist letter demanding permanent deletion and written confirmation of that deletion.
Who was affected?
This breach affects individuals who registered for Temple Adat Shalom Sisterhood’s Mah Jongg tournaments or purchased National Mah Jongg League cards through the Sisterhood. Because the underlying spreadsheets were compiled over multiple years, the affected group likely includes both current and past program participants.
The exact number of people impacted has not been publicly disclosed. However, the notification letter indicates the data set covered everyone listed in Sisterhood spreadsheets created through January 18, 2026. This suggests the affected population could span several years of tournament and card-sale registrants.
Because this incident involves a community and religious organization, many affected individuals may be longtime members or local residents with ongoing ties to the congregation. In addition, this type of breach can affect people who no longer actively participate but never had their information removed from older records.
What Information Was Potentially Exposed?
The exposed information centers on contact and activity details gathered through legitimate event registration. While it does not include financial account numbers or Social Security numbers, it still represents a meaningful privacy exposure for those affected.
- Full first and last names
- Email addresses
- Cell phone numbers or landlines
- Physical home addresses
- Recorded activity preferences, such as tournament or card-sale participation
Even without highly sensitive identifiers, this combination of data creates real risk. For example, scammers often use names paired with addresses and phone numbers to craft convincing, targeted messages. Because the first unauthorized campaign used the Temple’s own branding, this incident shows how easily such data can be used to impersonate a trusted organization.
In addition, affected individuals may see an increase in unwanted solicitation, spam calls, or phishing attempts referencing their tournament or card-sale history. This kind of contextual detail can make phishing messages feel more credible than a generic scam. As a result, people should stay alert even though no financial or medical data was involved.
What is the company doing?
Once Sisterhood leadership confirmed that the former volunteer had never deleted the retained data, they escalated their response. The Temple’s Board of Trustees was briefed on the situation, and the Temple President sent a formal written cease-and-desist letter to the individual involved.
That letter demanded the deletion of all copies of the data from every device, account, and storage location the volunteer may have used. It also required written confirmation once that deletion was completed. Alongside this action, the Sisterhood filed a formal notification with the California Attorney General and began notifying affected individuals directly.
The notification letter also gives recipients a way to specify which types of future communications they want to stop receiving. This includes tournament updates, card-sale messages, or all Sisterhood communications entirely. Because the organization does not sell or share data with outside parties, this incident was isolated to the former volunteer’s unauthorized retention and reuse.
What Should Affected Individuals Do?
Monitor Your Accounts and Credit Reports
Even though this breach did not expose financial account numbers, it’s still wise to check your accounts periodically. Unwanted contact based on stolen personal data can sometimes be a precursor to more serious scams. Regularly reviewing bank and credit card statements helps you catch unusual activity early.
You can also request a free credit report from each major credit bureau once a year. Reviewing these reports lets you spot unfamiliar accounts or inquiries. If you notice anything suspicious, report it right away to limit potential damage.
Stay Alert for Phishing Attempts
Because your name, email, phone number, and address may have circulated without authorization, you could become a target for phishing. These messages often reference real details, like your tournament registration, to appear legitimate. This makes them harder to spot than typical spam.
Avoid clicking links or downloading attachments from senders you don’t recognize. Instead, verify any unexpected message by contacting the Temple or Sisterhood directly using a phone number or email you already trust. When in doubt, it’s always safer to delete a suspicious message than to engage with it.
Take Control of Your Communication Preferences
If you received unsolicited advertising tied to this incident, reply to the notification email to specify your preferences. You can choose to opt out of Mah Jongg communications, card-sale messages, tournament updates, or all Sisterhood contact entirely. This gives you direct control over future outreach.
In addition, consider using a unique email address or phone number when signing up for community events going forward. Doing so makes it easier to trace where any future unwanted contact originates. This small step can add a helpful layer of protection for future registrations.
Keep Records and Know Your Legal Options
Save a copy of the notification letter you received, along with any suspicious follow-up messages. These records may become important if you experience ongoing unwanted contact or want to pursue legal action. Documentation is often the strongest evidence in any potential claim.
Individuals whose data was retained and misused after being told to stop may have legal options available. This is especially true when an organization was informed of misuse but the data was not deleted as promised. Speaking with a data breach attorney can help you understand what protections may apply to your specific situation.
More Information
Official data breach notification from California Attorney General
