Merchant One, Inc. notified the California Attorney General of an incident where an unknown individual may have accessed specific files in its system via a third-party IT provider. The company became aware of suspicious activity on February 24, 2020. The potentially impacted data included personal information such as names and addresses. Merchant One engaged forensic specialists, confirmed system security, implemented enhanced email security, multi-factor authentication, and additional training, and transitioned to a different IT provider. Identity monitoring services were offered to affected individuals.