Christian crowdfunding platform GiveSendGo suffered a breach that exposed donor information tied to the Canadian Freedom Convoy 2022 fundraiser and related campaigns. Reporting said attackers took the site offline, redirected visitors to GiveSendGone.wtf, and leaked data on more than 92,000 donors, including names and other personal details. VICE identified Aubrey Cottle, also known as Kirtaner, as publicly claiming responsibility for the intrusion, saying he targeted the platform over concerns about foreign political influence in convoy fundraising; reporting also said many donors were based in the United States, while Canadian donors contributed a larger share of the money.
A subsequent leak reportedly expanded the exposure to roughly 5 GB of internal data, including a 2.5 GB MySQL database dump, Bitbucket source code, customer service records, and limited payment-card information such as card last-four digits and expiration dates. The disclosures intensified scrutiny of GiveSendGo’s security after earlier reports of exposed identity documents on its servers, an unresolved researcher warning dating back to 2018, and a separate 2021 donor-data leak linked to fundraising for people involved in the January 6 Capitol riot. GiveSendGo CEO Jacob Wells condemned the breach as illegal and said law enforcement was expected to investigate, while Cottle said he received death threats after claiming involvement.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
On 2022-02-17, Aubrey Cottle publicly said he hacked GiveSendGo, took the site offline, redirected it, and leaked Freedom Convoy donor data. GiveSendGo CEO Jacob Wells condemned the breach and said the company expected a law enforcement investigation, potentially involving the FBI.
On 2022-02-15, reporting revealed another GiveSendGo leak affecting the Freedom Convoy and 'Adopt a Trucker' campaigns. DDoSecrets said it received about five gigabytes of data, including a MySQL database dump, Bitbucket source code, customer service information, and limited donor credit card data such as last four digits and expiration dates.
On 2022-02-14, reporting confirmed that names of Freedom Convoy donors were leaked following the GiveSendGo breach. This marked the public disclosure of the donor-data exposure tied to the convoy fundraising campaign.
By mid-February 2022, attackers breached GiveSendGo, defaced the site, redirected visitors to GiveSendGone.wtf, and exposed campaign and donor data tied to the Freedom Convoy 2022 fundraiser. The leak included personal details for more than 92,000 donors.
In 2021, GiveSendGo experienced a prior donor-data leak connected to fundraising for people involved in the January 6 Capitol riot. Later coverage cited this as an earlier security incident affecting the crowdfunding platform.
In 2018, a security researcher reported that GiveSendGo servers exposed sensitive identity documents and left a warning message. The issue was described as unresolved in later reporting, contributing to scrutiny of the platform's security practices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
vice.com
Open sourcedailydot.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.