Matador Recordings, LLC (d/b/a Matador Direct) notified customers of a data breach affecting its e-commerce websites. An unauthorized third party accessed customer information, including names, addresses, phone numbers, email addresses, payment card numbers, expiration dates, security codes (CVV), and account passwords. The incident occurred between April 28, 2015, and May 4, 2016, and was discovered on May 4, 2016, when the third-party website developer identified suspicious files. Matador engaged a cybersecurity firm and remediated the websites.