In February 2022, hackers breached GiveSendGo and leaked personal information for roughly 90,000 to 104,000 people who donated to the Canadian Freedom Convoy fundraiser. The data included names, email addresses, ZIP and postal codes, donation amounts, and IP addresses. Reporting by The Intercept and CBC identified Oath Keepers members, US public officials, and current and former Ontario police officers among the donors. The Ontario Provincial Police opened an internal conduct investigation into members who appeared on the list.
What happened
In February 2022, hackers breached GiveSendGo, a Christian crowdfunding platform. They leaked the donor records for the Canadian Freedom Convoy fundraiser, the protest that blocked downtown Ottawa for weeks that winter.
Estimates of the donor count vary by source. TechCrunch reported about 90,000 records. Reuters reported around 104,000. A widely cited copy of the data listed 92,845 donors. Contributions came to roughly $9.6 million. The leaked fields included donor names, email addresses, ZIP and postal codes, donation amounts, and IP addresses. Have I Been Pwned later indexed the breach.
The records were posted publicly and mirrored across multiple sites within days.
How it spread
GiveSendGo became the main fundraising platform for the convoy after GoFundMe removed the original campaign. Donations moved fast, and so did attention. The breach exported the donor table and put it in the open.
On February 17, The Intercept reported specific groups inside the leaked data: Oath Keepers members, US public officials, and Canadian police officers.
CBC News matched at least two dozen current and former members of the Ottawa Police Service and the Ontario Provincial Police to the donor list, cross-referencing postal codes, social media accounts, and public records. The OPP's Professional Standards Unit opened an internal conduct investigation into members who appeared to have donated.
Why this matters for first responders
The doxxing here did not run through a people-search broker. It ran through a payment platform's customer database. That is a different exposure surface than the one this site usually covers, and it carries its own lessons.
A political donation creates a record. That record sits on a server you do not control. If the platform is breached, your name, your location, and the cause you gave to can be linked together in public. For a sworn officer, the fallout ranged from an internal investigation to a personal-safety concern, depending on the agency and jurisdiction.
Any platform that processes payments tied to a cause, a candidate, or a movement can become a target for the same kind of leak.
What this means for your exposure
Broker-removal work covers the residential-address layer: the people-search sites that publish your home address, phone number, and relatives. It does not reach a breach like this one. Once a donor record is leaked and mirrored, there is no opt-out form to file.
The controls for this layer are different. Think carefully before giving to a politically sensitive cause through a platform you cannot vet. Where you can, use a payment method that does not tie directly to your home. Check a platform's breach history before you trust it with your name.
For the residential layer, see /doxxing. For how off-duty exposure adds to on-duty risk, see /law-enforcement.
What reduces this risk
The GiveSendGo breach is a doxxing risk most first responders never think about. A political donation through a payment platform creates a record on a server you do not control. When the platform is breached, your name, location, and the cause you supported can be linked in public. For a sworn officer, the fallout ranged from an internal investigation to a personal-safety concern, depending on the agency and jurisdiction. Broker removal does not reach this layer. Once a donor record leaks and is mirrored, there is no opt-out form to file. The controls that matter here are different: think carefully before giving to a politically sensitive cause through a platform you cannot vet, use a payment method that does not tie directly to your home where you can, and check a platform's breach history before you trust it with your name.
Public sources
- GiveSendGo, the Christian fundraising site, was hacked, leaking the data of donors who supported the Canadian truckers' protests — TechCrunch, 2022-02-14
- More data on Canada truck convoy donors leaked from website — Reuters, 2022-02-15
- Hacked GiveSendGo Records Reveal Oath Keepers, Cops, and Public Officials Donated to the Freedom Convoy — The Intercept, 2022-02-17
- Hackers Bring Down Site Used to Donate to Trucker Protest — The New York Times, 2022-02-14
- GiveSendGo data breach — Have I Been Pwned, 2022-02-14
- Police grappling with members who allegedly donated to 'Freedom Convoy' — CBC News, 2022-02-16
- Canada's convoy protest made everyone a doxer — Centre for International Governance Innovation, 2022-12-19