Spark Pay Online Store, a division of Capital One, N.A., disclosed a security event involving malicious code on a merchant website hosted by Spark Pay. The code allowed fraudsters to obtain customer payment information, including name, address, phone number, email, payment card number, expiration date, and CVV, for transactions made between April 10, 2017, and June 7, 2017. The company removed the code, notified card networks and law enforcement, and offered two years of credit monitoring.