The Crucible, an Oakland-based industrial arts organization, disclosed a data breach affecting transactions on TheCrucible.org between April 28, 2019, and February 27, 2020. Malicious code (a skimmer) embedded in an image file on the site captured customer payment data, including credit card numbers, CVVs, and personal information. The Crucible disabled payments, removed the code, and engaged in a forensic investigation. The incident was reported to the California Department of Justice.