Big Fish Games disclosed that an unknown criminal installed malware on its online billing and payment pages between December 24, 2014, and January 6, 2015. The malware intercepted customer payment information, including name, address, card number, expiration date, and CVV2 code. The incident was discovered on January 12, 2015. The company removed the malware, reported the incident to law enforcement and card networks, and offered one year of identity protection services to affected customers.