Sears Holdings Management Corporation notified customers that a vendor providing online support services for Sears.com and Kmart.com experienced a security incident. An unauthorized individual incorporated a malicious script into the vendor's code, collecting personal information (name, address) and payment card information from customers who completed online orders between September 27, 2017, and October 12, 2017. Sears was informed of the incident in mid-March 2018. Payment card companies were notified, and an investigation was conducted. No evidence suggests Sears' internal systems were accessed.