On December 21, 2022, Goodwill Industries appeared on the leak site operated by the karakurt ransomware group. The listing claims the attackers exfiltrated 403 GB of corporate data from Centrisys, a Wisconsin-based manufacturer of decanter centrifuges, and its subsidiary CNP Technology Water and Biosolids. Anyone whose personal or employment records passed through these companies may now face long-term exposure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Goodwill industries
Get alerted the next time Goodwill industries files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Goodwill industries’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak Listing
The karakurt leak site states that internal files were taken during a ransomware attack. It does not specify the exact number of affected individuals, the precise data types beyond “corporate data,” or whether customer, employee, or vendor records were included. The posting offers 403 GB of material and follows the group’s standard practice of publishing proof-of-exfiltration samples after initial extortion attempts. No ransom demand figure is listed on the page, and the disclosure does not indicate whether any data has been sold to third parties.
Why This Matters for You and Your Family
When a manufacturer like Centrisys loses control of internal files, the information often includes employee names, addresses, Social Security numbers, payroll details, and vendor contracts. If you or a family member ever worked at Centrisys, CNP, or any of their wastewater-industry partners, your personal data may be sitting in an attacker-controlled archive. Even basic contact information can be combined with other breaches to build a complete profile that leads to identity theft, tax fraud, or targeted phishing. The uncertainty around the exact contents makes it impossible to dismiss the risk.
Doxxing and Identity-Chain Risks
Leaked corporate files frequently contain email addresses, usernames, and internal notes that link professional identities to personal ones. Attackers or buyers can chain these details with gaming accounts, social-media handles, and prior breach records to locate home addresses, family relationships, and children’s online profiles. A single exposed work email can unlock password-reset paths across personal services, turning one industrial breach into a gateway for account takeovers and doxxing campaigns.