AeroGrow International, Inc. notified California AG that malware infiltrated its online servers between Oct 2014 and Apr 2015. The incident potentially exposed customer names, addresses, and credit card details (account number, expiration, CVV). AeroGrow does not store card data; it was captured in transit. The company hired forensic specialists, eradicated the malware, alerted law enforcement, and offered free identity protection via Experian.