Plant Therapy, a retailer of essential oils, notified the California AG of a data breach involving its third-party e-commerce provider. Between March 29 and May 11, 2018, malware was installed on the platform, potentially compromising payment card data (names, card numbers, expiration, CVV) of approximately 1,074 California residents. Plant Therapy engaged forensic investigators, notified the FBI, and provided 24 months of credit/identity monitoring via AllClear ID.
Affected (this filing): 1,074