Letter to the Editor: Trust on the Trail Broken: Data Breach Clouds 3500 Club’s Legacy

Posted

Recent disclosures regarding the governance of the Catskill 3500 Club have moved beyond internal disagreement and into a matter of significant public concern. As a community of hikers and outdoor enthusiasts, we entrust local organizations not just with our trail milestones, but with our sensitive personal information and the stewardship of our regional legacy.

Internal records recently brought to light have confirmed a material data security failure. In June 2023, a database containing the Personally Identifiable Information (PII) of 6,033 individuals—including full names, home addresses, phone numbers, and detailed financial payment histories—was exported and transmitted to an unsecured, private commercial server.

Under the New York SHIELD Act, organizations are legally mandated to implement reasonable safeguards and, crucially, to provide formal notification to all affected parties when such an exposure occurs. To date, nearly three years after this event, the 3500 Club Board has failed to issue this mandatory legal notification to the 6,000+ affected hikers.

This administrative negligence, alongside documented revenue misclassification and unauthorized asset movements, is now a matter of record with the NYS Attorney General’s Charities Bureau (File #26-025212).

When a non-profit operates with a lack of transparency—moving significant funds without board authorization and failing to meet state data privacy standards—it jeopardizes the trust of the community it serves. The legacy of the 3500 Club belongs to the hikers who have climbed these peaks, not to a leadership faction that treats statutory compliance as an inconvenience.

I urge all members and aspirants to protect their interests by inquiring with the Attorney General regarding the status of their data. The high peaks of the Catskills deserve professional stewardship; so do the people who hike them.

Kyle T. Bittner

Ulster Park