American Pharmacists Association (APhA) disclosed a cybersecurity incident where its website was defaced on May 28, 2012. Unauthorized access occurred between April 23 and May 28, 2012, resulting in the exfiltration of customer data including names, addresses, credit card numbers, and expiration dates. A separate notification indicated some records included driver's license numbers. APhA shut down servers, engaged forensic investigators, and notified law enforcement. Affected individuals were offered credit monitoring services.