Categories: Data Breach

Goodwill Discloses Data Breach on its ShopGoodwill Platform

Goodwill Discloses Data Breach on its ShopGoodwill Platform

American nonprofit Goodwill has disclosed a data breach that affected the accounts of customers using its ShopGoodwill.com e-commerce auction platform.

ShopGoodwill’s Vice President Ryan Smith said in data breach notification letters sent to impacted individuals that some of their personal contact information was exposed due to a site vulnerability.

Smith added that no payment information was exposed in the incident because ShopGoodwill does not store such data on its servers.

“We were recently alerted to an issue on our website which resulted in the exposure of some of your personal contact information to an unauthorized third party. This contact information includes your first and last name, email address, phone number, and mailing address,” Smith explained.

“No payment card information was exposed; ShopGoodwill does not store payment card information. While the third party accessed buyer contact information, they did not access your ShopGoodwill account.”

Also Read: Things to Know about the Spam Control Act (Singapore)

The nonprofit has fixed the ShopGoodwill vulnerability that led to exposure to personal contact information.

ShopGoodwill data breach notification letter (Troy Hunt)

“ShopGoodwill is committed to the security of your personal information and we apologize for any frustration or concern this incident may cause,” Smith added.

Also Read: The impact of GDPR and PDPA in Singapore

“If we learn of any additional relevant information, we will contact you immediately. If you have a question that has not been addressed in this communication, please email inquiries@shopgoodwill.info.”

Goodwill has served over 25 million people with disabilities or disadvantages worldwide in 2019 and helped more than 230,000 individuals train to find a job in banking, IT, and health care.

The nonprofit funds itself by selling donated clothing and household goods via an extensive network of thousands of retail thrift stores worldwide and on its ShopGoodwill.com online auction site.

A Goodwill spokesperson was not available for comment when contacted by BleepingComputer earlier today.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

1 month ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago