Totally Promotional disclosed that an unauthorized actor placed code on its website's payment platform to capture customer payment card information. The incident occurred in multiple windows between November 20, 2023, and October 20, 2024. Suspicious activity was identified on July 10, 2024. The company removed the malicious code and reviewed policies. Affected data includes names and payment card information.