OXO, a consumer goods retailer, disclosed a data breach affecting its e-commerce website. Unauthorized code was inserted into the site on or around July 1, 2018, collecting customer names, billing/shipping addresses, and credit card information. OXO discovered the incident on October 1, 2018, removed the code, engaged forensic consultants, and offered one year of free identity monitoring via Kroll to affected individuals.