Ransomware victim disclosure
← All victimsGoodwill Industries of North Central Pennsylvania
listed as Goodwill · Claimed by Interlock · listed 2 months ago
Status timeline
- Listed
Mar 26, 2026
- Data leaked
At a glance
- Group
- Interlock
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Mar 26, 2026
About the victim
AI dossier — public-source company profileGoodwill Industries of North Central Pennsylvania is a nonprofit organization dedicated to turning donations into jobs and employment opportunities. It provides employment for more than 700 people across 15 counties in Pennsylvania and one county in New York. The organization operates donation-driven retail and workforce development programs across its regional service area.
- Industry
- Nonprofit Workforce Development & Retail Thrift
- Employees
- 501-1000
Attack summary
Severity: high — Confirmed exfiltration and publication of PII belonging to employees and partners, plus financial documents, with data_published status indicating the data has been released publicly rather than merely threatened.The Interlock ransomware group claims to have exfiltrated and published hundreds of records containing personal data belonging to employees and partners, as well as financial documents, citing negligent security practices by the organization.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal data
- Partner personal data
- Financial documents
What the group claims
Goodwill Industries of North Central Pennsylvania is dedicated to turning donations into jobs, providing employment for more than 700 people across 15 counties in Pennsylvania and one county in New York. However, they have been extremely negligent and irresponsible regarding security, resulting in the compromise and online leak of hundreds of pieces of personal data belonging to employees and partners, as well as financial documents.
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
