Goodwill of Central and Coastal Virginia, Inc.
bd_3f8d34be783d8bde · schema v1 · pii pii-v1
Full breach record for Goodwill of Central and Coastal Virginia, Inc. →Goodwill of Central and Coastal Virginia, Inc. disclosed a ransomware incident on November 20, 2021, impacting IT systems. Approximately 17,800 current and former employees were notified that their PII, including SSNs and financial data, may have been exposed. The company did not pay the ransom, engaged forensic investigators, and provided 24 months of identity monitoring via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 20, 2021
Begins
Nov 20, 2021
Discovered
Dec 16, 2021
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteblackbytebd_4091d8a4608c138d2021-11-23 · +23dVerified by operator
Regulatory filings (2) · sorted by filing gap
- Indiana State AGbd_65bb0e88074d5e692021-12-16Verified
- Massachusetts State AGbd_856955d3b189c7cd2021-12-30 · +14dVerified by operator
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Dec 16 (IN), last Dec 30 (MA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.