Bebe Stores, Inc. detected suspicious activity on payment processing systems in its U.S., Puerto Rico, and U.S. Virgin Islands stores. The incident occurred between November 8 and November 26, 2014. Payment card data, including cardholder name, account number, expiration date, and verification code, may have been compromised. The company engaged a security firm, blocked the attack, and offered one year of credit monitoring to affected customers.