Goodwill claims it was hit by data breach

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

American nonprofit Goodwill has suffered a data breach that is affecting the users of its ShopGoodwill.com e-commerce auction platform. 

Reports say the company’s platform has had an exploitable vulnerability which malicious actors abused to make away with the full names, email addresses, phone numbers, and mailing addresses of its users. 

It's not known exactly how many customers were affected by the breach, but GoodWill says it has patched up the vulnerability.

Making use of stolen data

In a notification letter, which the company’s Vice President Ryan Smith sent out to affected customers, it was said that cyberattackers did not access any accounts, and that no financial data was taken. 

"We were recently alerted to an issue on our website which resulted in the exposure of some of your personal contact information to an unauthorized third party,” Smith said. 

“No payment card information was exposed; ShopGoodwill does not store payment card information. While the third party accessed buyer contact information, they did not access your ShopGoodwill account."

While stealing names, email addresses, phone numbers and mailing addresses may not seem like much, for cybercrooks - it’s plenty. This information can be used in identity theft, allowing malicious actors to pose online as their victims, and to either steal more sensitive data elsewhere, or to use this information in a phishing attack. 

This data is also useful in password cracking, as many people use things like birth dates, or physical addresses, as their passwords. It can be also used in credential stuffing, as consumers often use the same login data across numerous services.

The nonprofit helps people with disabilities worldwide and has, according to BleepingComputer, helped 230,000 individuals find a job in 2019. Its funding comes from the sales of donated goods, which can be purchased either in thrift shops around the world, or on the ShopGoodwill.com online auction site.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Blood donation firm reveals donor personal data stolen in cyberattack
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Major breach hits employee screening firm - 3.3 million affected as hackers steal DISA data
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
Zagg warns customers their data may have been stolen in third-party cyberattack
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Assassin's Creed Shadows
Assassin's Creed Shadows PS5 Pro details have been revealed and the biggest difference appears to be ray tracing
A collage of Iman Vellani's Kamala Khan in Marvels, Robert Downey Jr as Doctor Doom at Comic Con 2024, and Hailee Steinfeld's Kate Bishop in Hawkeye
'We take the comprehensive view': Joe and Anthony Russo drop big hint over Marvel heroes from Disney+ shows appearing in Avengers 5 and 6
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy