American Society for Clinical Pathology (ASCP) notified California of a cybersecurity attack on its e-commerce website (ascp.org) between March 30 and November 6, 2020. The attack potentially exposed payment card data (card numbers, expiration dates, CVVs) for customers who made purchases during that period. ASCP engaged forensic investigators, resolved the vulnerability, and implemented additional security safeguards. No evidence of misuse was found, and no specific count of affected individuals was disclosed.