Black Phoenix, Inc. disclosed a cybersecurity incident affecting its Black Phoenix Alchemy Lab (BPAL) website between May 1 and May 16, 2018. Malicious code injected into the AuthorizeNet checkout gateway harvested credit card data for approximately 150 transactions. The company reset passwords, neutralized the code, audited security, moved servers, and notified the FBI and local law enforcement. Data potentially exposed includes names, billing addresses, phone numbers, emails, and credit card details.
Affected (this filing): 150