San Antonio Shoemakers experienced a malware attack on checkout systems at US retail stores between April 21 and June 13, 2016. Malicious software collected payment card data including cardholder name, number, security code, and expiration date. The company engaged cybersecurity experts, cooperated with law enforcement (US Attorney's Office SDNY, Secret Service), and delayed notification for 30 days per law enforcement request. Affected customers were offered 24 months of identity protection.